<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SPLUNK TA to Write Log from SPLUNK HF server to S3 and SQS in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674734#M112927</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think HF/UF doesn't have any role here; main use case: we have a server need to write data from that server to AWS S3 Bucket; do we have any TA?&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jan 2024 19:56:10 GMT</pubDate>
    <dc:creator>SplunkDash</dc:creator>
    <dc:date>2024-01-18T19:56:10Z</dc:date>
    <item>
      <title>SPLUNK TA to Write Log from SPLUNK HF server to S3 and SQS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674715#M112921</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Do we have any SPLUNK TA that can write logs from SPLUNK Server with HF to AWS S3/SQS.&amp;nbsp; Any recommendation will be highly appreciated, thank you!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 17:38:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674715#M112921</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2024-01-18T17:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK TA to Write Log from SPLUNK HF server to S3 and SQS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674720#M112922</link>
      <description>&lt;P&gt;Does it have to use an HF?&amp;nbsp; The Export Everything app (&lt;A href="https://splunkbase.splunk.com/app/5738" target="_blank"&gt;https://splunkbase.splunk.com/app/5738&lt;/A&gt;) can write to S3&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 18:06:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674720#M112922</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-01-18T18:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK TA to Write Log from SPLUNK HF server to S3 and SQS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674723#M112923</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for your quick response.&lt;/P&gt;&lt;P&gt;It's not exporting SPLUNK search results, it about writing Logs into S3 bucket using SPLUNK TA. For Example, we have some Application logs within server, we would prefer to use SPLUNK TA to write those logs into S3 Buckets from there and ingest data from S3/SQS. This server has the HF install on them. We cannot perform direct ingestion from that server due to security reason.&amp;nbsp; Any thoughts or recommendations&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 18:21:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674723#M112923</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2024-01-18T18:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK TA to Write Log from SPLUNK HF server to S3 and SQS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674730#M112926</link>
      <description>&lt;P&gt;Please tell us more about the environment.&amp;nbsp; Can the server relay data to Splunk via an intermediate forwarder?&amp;nbsp; Why is an HF installed instead of a Universal Forwarder (UF)?&amp;nbsp; UFs have a much smaller footprint and attack surface.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 19:42:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674730#M112926</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-01-18T19:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK TA to Write Log from SPLUNK HF server to S3 and SQS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674734#M112927</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think HF/UF doesn't have any role here; main use case: we have a server need to write data from that server to AWS S3 Bucket; do we have any TA?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 19:56:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674734#M112927</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2024-01-18T19:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK TA to Write Log from SPLUNK HF server to S3 and SQS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674933#M112957</link>
      <description>&lt;P&gt;Here's an untested idea.&amp;nbsp; Install an HF on the server and use Splunk's Ingest Actions feature to write the data to S3.&amp;nbsp; It's not clear if the HF will be happy only writing to S3 or if it also will want to send to an indexer.&lt;/P&gt;&lt;P&gt;See &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.2/Data/DataIngest#Heavy_forwarders_managed_through_a_deployment_server" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.2/Data/DataIngest#Heavy_forwarders_managed_through_a_deployment_server&lt;/A&gt; for details, including the need for a Deployment Server.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2024 18:32:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674933#M112957</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-01-20T18:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK TA to Write Log from SPLUNK HF server to S3 and SQS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674938#M112958</link>
      <description>&lt;P&gt;If you look into outputs.conf specs, you'll see that it supports both SQS output as well as RFS output which should be able to write into S3 buckets. Never used them myself though so I have no idea how they work and whether they require HF or if they will work with UF as well (I suspect the former).&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2024 22:31:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-TA-to-Write-Log-from-SPLUNK-HF-server-to-S3-and-SQS/m-p/674938#M112958</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-20T22:31:35Z</dc:date>
    </item>
  </channel>
</rss>

