Hello,
I am using Standalone Splunk Enterprise Version, No Indexer, No Search heads, No Heavy Forwarders.
I want to forward Splunk Indexed Logs to the Third Party SIEM Alienvault.
I already went through some solutions that require Heavy Forwarder or Indexer. Is there any method that I can forward these collected logs from Splunk to Alienvault.
Regards
Kuldeep Pawar
Thanks, everyone this resolved my issue
http://docs.splunk.com/Documentation/CEFapp/2.0.0/DeployCEFapp/AboutSplunkAppforCEF