Getting Data In

Can we use heavy forwarder so the output can be send to Logstash host and port? No way to stream data to AWS Kinesis?

nikk
Engager

Hi everyone, 

I am trying to redirect logs from Splunk Enterprise locally installed to OpenSearch Logstash or to Aws Kinesis. 

I am quite new to Splunk so it brings troubles in getting the idea how it can be achieved. 
Am I right ? : 
1. We can use heavy forwarder so the output can be send to Logstash host and port ? 
2. No way to stream data to Aws Kinesis even with add-ons nither CLI nor Web Splunk. 

Probably it is possible to use splunk sdk / api for getting stream of data so it can be programmatically transferred to Kinesis by aws jdk. 

I hope someone has some experience with it. 

Thanks ! 

Labels (3)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@nikk - Answers to your questions below: 

  1. Yes, you need to use HF
    1. Reference - https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd
  2. Splunk Add-on for AWS is to collect the data in Splunk from AWS, not to send data to AWS Kinesis
    1. To do that you could use the above-given reference
    2. forward the data to another Linux machine
    3. write a custom script to retrieve the data being sent on a port by Splunk
    4. and send it to AWS Kinesis

 

I hope this helps!!! Kindly upvote if it does!!!

View solution in original post

VatsalJagani
SplunkTrust
SplunkTrust

@nikk - Answers to your questions below: 

  1. Yes, you need to use HF
    1. Reference - https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd
  2. Splunk Add-on for AWS is to collect the data in Splunk from AWS, not to send data to AWS Kinesis
    1. To do that you could use the above-given reference
    2. forward the data to another Linux machine
    3. write a custom script to retrieve the data being sent on a port by Splunk
    4. and send it to AWS Kinesis

 

I hope this helps!!! Kindly upvote if it does!!!

Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...