<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send logs from Splunk Enterprise to Elastic Search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Send-logs-from-Splunk-Enterprise-to-Elastic-Search/m-p/429338#M171624</link>
    <description>&lt;P&gt;@Sukisen1981 Thanks for the information. &lt;/P&gt;</description>
    <pubDate>Mon, 06 May 2019 13:38:50 GMT</pubDate>
    <dc:creator>Said7</dc:creator>
    <dc:date>2019-05-06T13:38:50Z</dc:date>
    <item>
      <title>Send logs from Splunk Enterprise to Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Send-logs-from-Splunk-Enterprise-to-Elastic-Search/m-p/429335#M171621</link>
      <description>&lt;P&gt;Hi, i hope someone can help us, please. &lt;/P&gt;

&lt;P&gt;We have to send our logs that we receive from Firewall's, Sysmon, etc from Splunk Enterprise to another device called Elastic Search throught syslog. &lt;/P&gt;

&lt;P&gt;Our configuration  by Splunk is in /opt/splunk and we create a file in /opt/splunk/etc/system/local called outputs.conf &lt;/P&gt;

&lt;P&gt;Our configuration is next: &lt;/P&gt;

&lt;P&gt;[root@SPLUNK2 local]# cat outputs.conf&lt;/P&gt;

&lt;P&gt;defaultGroup = syslogGroup&lt;/P&gt;

&lt;P&gt;[syslog: syslogGroup]&lt;BR /&gt;
server = xxx.xxx.xxx.xxx:514&lt;/P&gt;

&lt;P&gt;We restart the splunk throught GUI in settings &amp;gt; server control, but we didn't see logs outgoing.&lt;/P&gt;

&lt;P&gt;Regargds&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 22:44:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Send-logs-from-Splunk-Enterprise-to-Elastic-Search/m-p/429335#M171621</guid>
      <dc:creator>Said7</dc:creator>
      <dc:date>2019-04-29T22:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Send logs from Splunk Enterprise to Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Send-logs-from-Splunk-Enterprise-to-Elastic-Search/m-p/429336#M171622</link>
      <description>&lt;P&gt;check this out - &lt;A href="https://logz.io/blog/migrating-from-splunk-to-elk/"&gt;https://logz.io/blog/migrating-from-splunk-to-elk/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 20:16:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Send-logs-from-Splunk-Enterprise-to-Elastic-Search/m-p/429336#M171622</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-04-30T20:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Send logs from Splunk Enterprise to Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Send-logs-from-Splunk-Enterprise-to-Elastic-Search/m-p/429337#M171623</link>
      <description>&lt;P&gt;The easiest method would be to install Logstash on the box where you are collecting logs and use it to forward them on to ELK.&lt;/P&gt;

&lt;P&gt;Logstash is essentially Elastic's equivalent of Splunks Universal Forwarder.&lt;/P&gt;

&lt;P&gt;It's easy to set up and designed to do exactly what you're attempting.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 20:51:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Send-logs-from-Splunk-Enterprise-to-Elastic-Search/m-p/429337#M171623</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2019-04-30T20:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Send logs from Splunk Enterprise to Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Send-logs-from-Splunk-Enterprise-to-Elastic-Search/m-p/429338#M171624</link>
      <description>&lt;P&gt;@Sukisen1981 Thanks for the information. &lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 13:38:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Send-logs-from-Splunk-Enterprise-to-Elastic-Search/m-p/429338#M171624</guid>
      <dc:creator>Said7</dc:creator>
      <dc:date>2019-05-06T13:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Send logs from Splunk Enterprise to Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Send-logs-from-Splunk-Enterprise-to-Elastic-Search/m-p/429339#M171625</link>
      <description>&lt;P&gt;@codebuilder, thanks for your answer, we are checking the documentation of splunk to try send the logs without install logstash. &lt;/P&gt;

&lt;P&gt;[&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Forwarding/Forwarddatatothird-partysystemsd"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt;]&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 13:42:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Send-logs-from-Splunk-Enterprise-to-Elastic-Search/m-p/429339#M171625</guid>
      <dc:creator>Said7</dc:creator>
      <dc:date>2019-05-06T13:42:35Z</dc:date>
    </item>
  </channel>
</rss>

