<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is there a way to transfer data from Splunk Search Head  via Scheduled Search to third party system through syslog? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-transfer-data-from-Splunk-Search-Head-via/m-p/519926#M87911</link>
    <description>&lt;P&gt;Requirement is to send data from Splunk to PTA tool using Scheduled Search on Search Head.&lt;/P&gt;&lt;P&gt;The Data should be filtered on some parameters and filtered data/events are sent to PTA in regular intervals. Like Every one hours the Events should be filtered and sent to PTA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Sep 2020 13:43:49 GMT</pubDate>
    <dc:creator>potnuru</dc:creator>
    <dc:date>2020-09-16T13:43:49Z</dc:date>
    <item>
      <title>Is there a way to transfer data from Splunk Search Head  via Scheduled Search to third party system through syslog?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-transfer-data-from-Splunk-Search-Head-via/m-p/519926#M87911</link>
      <description>&lt;P&gt;Requirement is to send data from Splunk to PTA tool using Scheduled Search on Search Head.&lt;/P&gt;&lt;P&gt;The Data should be filtered on some parameters and filtered data/events are sent to PTA in regular intervals. Like Every one hours the Events should be filtered and sent to PTA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 13:43:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-transfer-data-from-Splunk-Search-Head-via/m-p/519926#M87911</guid>
      <dc:creator>potnuru</dc:creator>
      <dc:date>2020-09-16T13:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to transfer data from Splunk Search Head  via Scheduled Search to third party system through syslog?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-transfer-data-from-Splunk-Search-Head-via/m-p/519939#M87912</link>
      <description>&lt;P&gt;I don't know what is your case. you can do using below procedure:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;create your search and write your results to csv file using outputcsv command.&lt;/LI&gt;&lt;LI&gt;create inputs.conf to monitor the file and create outputs.conf to forward data using [syslog] on search head.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 16 Sep 2020 14:12:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-transfer-data-from-Splunk-Search-Head-via/m-p/519939#M87912</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-16T14:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to transfer data from Splunk Search Head  via Scheduled Search to third party system through syslog?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-transfer-data-from-Splunk-Search-Head-via/m-p/520581#M87981</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129407"&gt;@thambisetty&lt;/a&gt;&amp;nbsp;We need to forward the raw data from Splunk to CyberArk PTA(3rd Party) tool.&lt;/P&gt;&lt;P&gt;We need to forward the data through SYSLOG TCP. (PTA will listen to SYSLOG TCP on xyz port).&lt;/P&gt;&lt;P&gt;Is there any option to forward the data from Search Head without saving it locally?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 10:36:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-transfer-data-from-Splunk-Search-Head-via/m-p/520581#M87981</guid>
      <dc:creator>potnuru</dc:creator>
      <dc:date>2020-09-21T10:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to transfer data from Splunk Search Head  via Scheduled Search to third party system through syslog?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-transfer-data-from-Splunk-Search-Head-via/m-p/520602#M87986</link>
      <description>&lt;P&gt;you can't directly forward the search results from search head to 3rd party servers.&lt;/P&gt;&lt;P&gt;you can do it directly from Heavy forwarder/Indexer to 3rd syslog server.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.6/Search/Forwarddatatothirdpartysystems#:~:text=To%20forward%20data%20to%20third,conf%20files" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.6/Search/Forwarddatatothirdpartysystems#:~:text=To%20forward%20data%20to%20third,conf%20files&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 12:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-transfer-data-from-Splunk-Search-Head-via/m-p/520602#M87986</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-21T12:24:13Z</dc:date>
    </item>
  </channel>
</rss>

