<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk integration with other tool in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/534774#M89722</link>
    <description>&lt;P&gt;Universal Forwarders can send data only to another Splunk instances. You should setup outputs.conf only on indexers or heavy forwarders to forward data to third party. You can select data by using host, source, sourcetype or regex based on data contents.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jan 2021 11:02:28 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2021-01-05T11:02:28Z</dc:date>
    <item>
      <title>Splunk integration with other tool</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/534681#M89711</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having a single instance of Splunk enterprise on my environment ,Is there a way to forward the Splunk data to other SIEM product on required basis.&lt;/P&gt;&lt;P&gt;Could you please help us to provide the details to procedure on this.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 11:56:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/534681#M89711</guid>
      <dc:creator>splkadmin</dc:creator>
      <dc:date>2021-01-04T11:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk integration with other tool</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/534753#M89718</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230015"&gt;@splkadmin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can see options sending data to third parties on below document.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 05:32:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/534753#M89718</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-05T05:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk integration with other tool</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/534770#M89721</link>
      <description>&lt;P&gt;In that case do we need to add the output.conf&amp;nbsp; on each client server that i have installed a universal forwarder or should I add only to the Splunk enterprise instance that suppose to forward the all client logs to the third party server.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 10:20:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/534770#M89721</guid>
      <dc:creator>splkadmin</dc:creator>
      <dc:date>2021-01-05T10:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk integration with other tool</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/534774#M89722</link>
      <description>&lt;P&gt;Universal Forwarders can send data only to another Splunk instances. You should setup outputs.conf only on indexers or heavy forwarders to forward data to third party. You can select data by using host, source, sourcetype or regex based on data contents.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 11:02:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/534774#M89722</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-05T11:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk integration with other tool</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/535642#M89830</link>
      <description>&lt;P&gt;Thank you for your reply ..&lt;/P&gt;&lt;P&gt;Ok I have single instance of Splunk&amp;nbsp; enterprise and installed a universal forwarder on all the client.&lt;/P&gt;&lt;P&gt;Now I have to sent data to third party SIEM systems..&lt;/P&gt;&lt;P&gt;Should I configure only output.conf or just add the forwarded IP on Splunk instance console ?&lt;/P&gt;&lt;P&gt;do we able to configure a props.conf&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;transforms.conf on same instance? or do I require heavy forwarder to do that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 12:32:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/535642#M89830</guid>
      <dc:creator>splkadmin</dc:creator>
      <dc:date>2021-01-13T12:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk integration with other tool</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/535694#M89843</link>
      <description>&lt;P&gt;You can use single-instance Splunk Enterprise to forward data using methods/samples provided in the document. You do not need to have a heavy forwarder.&lt;/P&gt;&lt;P&gt;You need to configure outputs.conf and also props.conf, transforms.conf in order to route data.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 17:54:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-integration-with-other-tool/m-p/535694#M89843</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-13T17:54:41Z</dc:date>
    </item>
  </channel>
</rss>

