Can a splunk forwarder send logs directly to an S3 bucket without any other intervention as well as send to the splunk indexer? I've looked at the articles that might pertain to this question and the only one that is a definitive yes/no response was almost 4 years ago now. Perhaps something has changed in that time? I'm looking for yes the forwarder can do that and here's how or no the forwarder cannot do that. I've looked at this documentation as well https://docs.splunk.com/Documentation/Splunk/7.3.0/Forwarding/Forwarddatatothird-partysystemsd
and it doesn't really clear it up because as I'm not sure it would let you put the FQDN of the S3 bucket in there on port 443.
Thanks for responding to the question. The issue is I don't want my data stored in splunk format. I want the raw logs written to S3 such that we maintain a copy of all raw logging for other purposes.