Can a splunk forwarder send logs directly to an S3 bucket without any other intervention as well as send to the splunk indexer? I've looked at the articles that might pertain to this question and the only one that is a definitive yes/no response was almost 4 years ago now. Perhaps something has changed in that time? I'm looking for yes the forwarder can do that and here's how or no the forwarder cannot do that. I've looked at this documentation as well https://docs.splunk.com/Documentation/Splunk/7.3.0/Forwarding/Forwarddatatothird-partysystemsd
and it doesn't really clear it up because as I'm not sure it would let you put the FQDN of the S3 bucket in there on port 443.
What you could do is to use the export scripts in the Python SDK of Splunk to export Splunk data into S3 buckets
Thanks for responding to the question. The issue is I don't want my data stored in splunk format. I want the raw logs written to S3 such that we maintain a copy of all raw logging for other purposes.
No, how should this work? S3 is an object store and thus the UF would need to be able to talk to the API of the object store.
The UF can't do that right now.
Skalli
Thanks. Glad somebody could just say no to the question.