<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to forwarded logs from Splunk to MCAS in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460146#M79442</link>
    <description>&lt;P&gt;Thanks a lot &lt;/P&gt;</description>
    <pubDate>Wed, 20 May 2020 06:26:38 GMT</pubDate>
    <dc:creator>rayar</dc:creator>
    <dc:date>2020-05-20T06:26:38Z</dc:date>
    <item>
      <title>How to forwarded logs from Splunk to MCAS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460138#M79434</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;What will be the best way to implement the below request ?&lt;/P&gt;

&lt;P&gt;We need to configure the some logs to be forwarded from Splunk to MCAS Server (Server in the same network like Splunk server )&lt;BR /&gt;
Logs should be forwarded in Syslog or FTP and based on a specific query &lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 13:11:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460138#M79434</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2020-05-19T13:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to forwarded logs from Splunk to MCAS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460139#M79435</link>
      <description>&lt;P&gt;See the docs at &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Forwarding/Forwarddatatothird-partysystemsd"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt; .  While some filtering is possible, you cannot forward the results of a query.&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 13:45:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460139#M79435</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-19T13:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to forwarded logs from Splunk to MCAS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460140#M79436</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
I am getting "Hi! This page does not exist, or has been removed from the Documentation."&lt;BR /&gt;
so is there another way to send search results to external system  ?&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 13:48:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460140#M79436</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2020-05-19T13:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to forwarded logs from Splunk to MCAS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460141#M79437</link>
      <description>&lt;P&gt;Splunk didn't like the period at the end of the sentence.  Try the revised answer.&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 14:06:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460141#M79437</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-19T14:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to forwarded logs from Splunk to MCAS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460142#M79438</link>
      <description>&lt;P&gt;thanks , I was able to open the doc &lt;/P&gt;

&lt;P&gt;so there is no way to sent the results of such query to external system   ?&lt;/P&gt;

&lt;P&gt;index=websense AND act="Permitted"&lt;BR /&gt;
| fields _time, suser, src, dst, act, request, in, out&lt;BR /&gt;
| convert timeformat="%Y-%m-%d %H:%M:%S" ctime(_time) as Time&lt;BR /&gt;
| table  Time, suser, src, dst, act, request, in, out &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:30:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460142#M79438</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2020-09-30T05:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to forwarded logs from Splunk to MCAS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460143#M79439</link>
      <description>&lt;P&gt;No straightforward way.  You could schedule a report that saves query results in a CSV file and use a cron job to ship that file to another system.&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 14:30:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460143#M79439</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-19T14:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to forwarded logs from Splunk to MCAS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460144#M79440</link>
      <description>&lt;P&gt;and if I want to send in CEF format to the MCAS server &lt;BR /&gt;
where I define the target server  ? &lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 14:45:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460144#M79440</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2020-05-19T14:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to forwarded logs from Splunk to MCAS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460145#M79441</link>
      <description>&lt;P&gt;Your cron job could invoke a Python script that does the conversion.  The target server could be in the script or an external configurable.&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 16:41:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460145#M79441</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-19T16:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to forwarded logs from Splunk to MCAS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460146#M79442</link>
      <description>&lt;P&gt;Thanks a lot &lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 06:26:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forwarded-logs-from-Splunk-to-MCAS/m-p/460146#M79442</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2020-05-20T06:26:38Z</dc:date>
    </item>
  </channel>
</rss>

