I want to send incoming logs to external server like ELK from Splunk Instance. Generally, In documentation only "how Splunk forwarders can send to third party systems" is written. Is it possible to send incoming logs from Splunk server to external systems? And How?
I want to use Splunk Enterprise as our main SIEM production. But to run some scripts and use logs in our R&D activities, We want to send logs from Splunk Enterprise Server to ELK. We have done this but Splunk sent logs parsed. So we couldnt see raw data. If is it possible we want to get logs in JSON format.
I think the section of the docs you want is the route and filter data. Specifically, maybe, this part of it about sending data to third parties.
If those aren't what you need, could you provide a bit more information as to why not, or provide more specifics about exactly what you are trying to do so we can try to modify those for your needs a bit?
Thanks and Happy Splunking,
Rich