Question: We are using Commvault Metallic to backup our O365 cloud-based user data in the Microsoft GCC. How can we send the Commvault transaction logs to our on-prem Splunk servers for event analysis and reporting?
@pingli Hello, You can forward the data from your Commvault Metallic Saas Solution to Splunk using the API's or HEC tokens etc. Please find the below details for your reference.
https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/UsetheHTTPEventCollector
https://dev.splunk.com/enterprise/docs/devtools/httpeventcollector/