All Apps and Add-ons

about forwarding data from Splunk to non-Splunk side

makhambayeva
New Member

How can we forward data from Splunk to non-Splunk (third side)?
In fact, I need to forward all data, which came on specific port on Splunk, to another SIEM.
Do I need to configure only outputs.conf or i need to configure reseiver also? and how?

0 Karma

solarboyz1
Builder

If you want to send all data to BOTH splunk and non-splunk, you should only need to modify your outputs.conf:.
https://docs.splunk.com/Documentation/Forwarder/7.2.5/Forwarder/Configureforwardingwithoutputs.conf

[tcpout]
defaultGroup=splunk, siem 

[tcpout:splunk]
disabled=false
server=10.1.12.1:9997

[tcpout:siem]
disabled=false
sendCookedData=false
server=10.1.12.2:1234
0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...