<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: would like to send logs from Splunk to Qradar? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425399#M95488</link>
    <description>&lt;P&gt;Let's start with what kind of data you want to forward. Do you just want to route a copy of some of the data you ingest into splunk also to  qradar? Or do you want to send the result of some search / alert / whatever to QRadar?&lt;/P&gt;</description>
    <pubDate>Thu, 07 Mar 2019 15:42:34 GMT</pubDate>
    <dc:creator>FrankVl</dc:creator>
    <dc:date>2019-03-07T15:42:34Z</dc:date>
    <item>
      <title>would like to send logs from Splunk to Qradar?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425398#M95487</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;got a requirement to send logs from Splunk to Qradar. I have gone through few splunk docs, but I couldn't get proper idea on how to start with this requirement. I was able to find some info from IBM knowledge center, as per documentation there is a Qradar app for splunk data forwarding. but i am not sure how it will work.&lt;/P&gt;

&lt;P&gt;please let me know if anyone have knowledge on this? &lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 13:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425398#M95487</guid>
      <dc:creator>niha1318</dc:creator>
      <dc:date>2019-03-07T13:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: would like to send logs from Splunk to Qradar?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425399#M95488</link>
      <description>&lt;P&gt;Let's start with what kind of data you want to forward. Do you just want to route a copy of some of the data you ingest into splunk also to  qradar? Or do you want to send the result of some search / alert / whatever to QRadar?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 15:42:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425399#M95488</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-07T15:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: would like to send logs from Splunk to Qradar?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425400#M95489</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;we have already ingested data into splunk, we got thousand's of hosts for specific IIS logs. but we don't want to send all of them, we particularly want to send 75 hosts to qradar.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 10:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425400#M95489</guid>
      <dc:creator>niha1318</dc:creator>
      <dc:date>2019-03-08T10:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: would like to send logs from Splunk to Qradar?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425401#M95490</link>
      <description>&lt;P&gt;But do you want to export previously ingested data from Splunk, or do you want to implement a (partial) parallel feed to both platforms?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 10:26:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425401#M95490</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-08T10:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: would like to send logs from Splunk to Qradar?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425402#M95491</link>
      <description>&lt;P&gt;we wanted to export previously ingested data from splunk to qradar.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 14:06:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425402#M95491</guid>
      <dc:creator>niha1318</dc:creator>
      <dc:date>2019-03-08T14:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: would like to send logs from Splunk to Qradar?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425403#M95492</link>
      <description>&lt;P&gt;&lt;EM&gt;"we wanted to export previously ingested data from splunk to qradar."&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;If it is a one off, you could do a search and export the events to csv (use the &lt;CODE&gt;| fields _raw&lt;/CODE&gt; command to restrict the export to just the raw data).&lt;/P&gt;

&lt;P&gt;That can also be automated with a saved search that exports to CSV and I guess also through the REST API.&lt;/P&gt;

&lt;P&gt;For more information, see: &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Search/Exportsearchresults"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Search/Exportsearchresults&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 14:14:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/would-like-to-send-logs-from-Splunk-to-Qradar/m-p/425403#M95492</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-08T14:14:32Z</dc:date>
    </item>
  </channel>
</rss>

