How can we forward data from Splunk to non-Splunk (third side)?
In fact, I need to forward all data, which came on specific port on Splunk, to another SIEM.
Do I need to configure only outputs.conf or i need to configure reseiver also? and how?
If you want to send all data to BOTH splunk and non-splunk, you should only need to modify your outputs.conf:.
https://docs.splunk.com/Documentation/Forwarder/7.2.5/Forwarder/Configureforwardingwithoutputs.conf
[tcpout]
defaultGroup=splunk, siem
[tcpout:splunk]
disabled=false
server=10.1.12.1:9997
[tcpout:siem]
disabled=false
sendCookedData=false
server=10.1.12.2:1234