<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Cloud Data Input in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Data-Input/m-p/709070#M29067</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;When an organization is&amp;nbsp; having Hybrid deployment , so they using Splunk cloud service too, can data be sent directly to Splunk Cloud, for example there is a SaaS application which only has an option to send logs over syslog , how can this be achieved while using Splunk cloud. What are the options for Data input here. If someone can elaborate.&lt;/P&gt;&lt;P&gt;Thanking you in advance,&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Moh&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jan 2025 11:54:21 GMT</pubDate>
    <dc:creator>mohsplunking</dc:creator>
    <dc:date>2025-01-17T11:54:21Z</dc:date>
    <item>
      <title>Splunk Cloud Data Input</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Data-Input/m-p/709070#M29067</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;When an organization is&amp;nbsp; having Hybrid deployment , so they using Splunk cloud service too, can data be sent directly to Splunk Cloud, for example there is a SaaS application which only has an option to send logs over syslog , how can this be achieved while using Splunk cloud. What are the options for Data input here. If someone can elaborate.&lt;/P&gt;&lt;P&gt;Thanking you in advance,&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Moh&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 11:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Data-Input/m-p/709070#M29067</guid>
      <dc:creator>mohsplunking</dc:creator>
      <dc:date>2025-01-17T11:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Data Input</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Data-Input/m-p/709071#M29068</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;you can send or pull data into SCP. It’s totally depends on what is your SaaS system where you try to get this data. Currently quite many SaaS can send data via HEC to splunk. Another option is that they have REST api where you can query that data via modular inputs. Time by time there could be some other options too.&lt;/P&gt;&lt;P&gt;You should start with asking this from your SaaS vendor if they have any integration to Splunk. Also you could use google to found any other documentation for it.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 12:12:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Data-Input/m-p/709071#M29068</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-17T12:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Data Input</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Data-Input/m-p/709072#M29069</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234071"&gt;@mohsplunking&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set up a syslog forwarder to receive data from the SaaS application and then forward it to the Splunk Cloud. You can send data via HEC token also.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 12:14:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Data-Input/m-p/709072#M29069</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-01-17T12:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Data Input</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Data-Input/m-p/709073#M29070</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234071"&gt;@mohsplunking&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You cannot send syslog data directly to Splunk Cloud. You must use a Splunk Universal Forwarder or Splunk Heavy Forwarder to ingest the UDP syslog and send it to Splunk Cloud.&lt;/P&gt;&lt;P&gt;You can see the documentation about &amp;nbsp;syslog on Splunk Cloud below.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/HowSplunkEnterprisehandlessyslogdata?_gl=1*12ydeef*_gcl_au*NTg5NjI5Njc4LjE3MzMzMTc5NjM.*FPAU*ODY1MjI3NjcxLjE3MzA2NTMxMjA.*_ga*MTY5MTI0MjM4Ny4xNzMzMzE3OTY0*_ga_5EPM2P39FV*MTczNzExNTg2Ny4xNDIuMS4xNzM3MTE1OTEwLjAuMC4xOTM0Mzg5NzY3*_fplc*Vk1QNTNEUzZzaXcxJTJGdDlrUWZHRTdjVUZlN2c0NkVjMjRXYmtibyUyQkk1QTJqeDdQJTJGSDhPS09JYjJSY1dkOEtRaFp6bWZrMFFLMmhvdUg5T1Bpdk5RcTNxRWlXdXFzWVBHek1kdjhUQ3ZCb3UwUXE4cFJQNHdhJTJCREJDcE1kR1ElM0QlM0Q." target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/HowSplunkEnterprisehandlessyslogdata&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 12:16:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Data-Input/m-p/709073#M29070</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2025-01-17T12:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Data Input</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Data-Input/m-p/709074#M29071</link>
      <description>&lt;P&gt;It’s exactly that way.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;you need to understand your situation. Even there is some technical details mentioned you must understand the big picture, if you really want to utilize that data.&lt;/LI&gt;&lt;LI&gt;define your options&lt;/LI&gt;&lt;LI&gt;select best option&lt;/LI&gt;&lt;LI&gt;implement it&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;In real business You cannot start directly from step 4 if you want to get working solution with reasonable costs.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 12:37:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Cloud-Data-Input/m-p/709074#M29071</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-17T12:37:24Z</dc:date>
    </item>
  </channel>
</rss>

