Reporting

Is it possible to send logs from Splunk Enterprise server to ELK?

harunglec
New Member

I want to send incoming logs to external server like ELK from Splunk Instance. Generally, In documentation only "how Splunk forwarders can send to third party systems" is written. Is it possible to send incoming logs from Splunk server to external systems? And How?

Tags (1)
0 Karma

harunglec
New Member

I want to use Splunk Enterprise as our main SIEM production. But to run some scripts and use logs in our R&D activities, We want to send logs from Splunk Enterprise Server to ELK. We have done this but Splunk sent logs parsed. So we couldnt see raw data. If is it possible we want to get logs in JSON format.

0 Karma

Richfez
SplunkTrust
SplunkTrust

I think the section of the docs you want is the route and filter data. Specifically, maybe, this part of it about sending data to third parties.

If those aren't what you need, could you provide a bit more information as to why not, or provide more specifics about exactly what you are trying to do so we can try to modify those for your needs a bit?

Thanks and Happy Splunking,
Rich

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...