Hi,
is it possible to join Splunk with Kolide, so I could see eventlogs? Thank you
There are a few ways to onboard data into Splunk. Perhaps one or more of them apply to Kolide.
Install a universal forwarder on the server to send log files to Splunk
Have the server send syslog data to Splunk via a syslog server or Splunk Connect for Syslog
Use the server's API to extract data for indexing
Use Splunk DB Connect to pull data from the server's SQL database.