Getting Data In

How to forwarded logs from Splunk to MCAS

rayar
Communicator

Hi

What will be the best way to implement the below request ?

We need to configure the some logs to be forwarded from Splunk to MCAS Server (Server in the same network like Splunk server )
Logs should be forwarded in Syslog or FTP and based on a specific query

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

See the docs at https://docs.splunk.com/Documentation/Splunk/8.0.3/Forwarding/Forwarddatatothird-partysystemsd . While some filtering is possible, you cannot forward the results of a query.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

See the docs at https://docs.splunk.com/Documentation/Splunk/8.0.3/Forwarding/Forwarddatatothird-partysystemsd . While some filtering is possible, you cannot forward the results of a query.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

rayar
Communicator

Hi
I am getting "Hi! This page does not exist, or has been removed from the Documentation."
so is there another way to send search results to external system ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk didn't like the period at the end of the sentence. Try the revised answer.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

rayar
Communicator

thanks , I was able to open the doc

so there is no way to sent the results of such query to external system ?

index=websense AND act="Permitted"
| fields _time, suser, src, dst, act, request, in, out
| convert timeformat="%Y-%m-%d %H:%M:%S" ctime(_time) as Time
| table Time, suser, src, dst, act, request, in, out

0 Karma

richgalloway
SplunkTrust
SplunkTrust

No straightforward way. You could schedule a report that saves query results in a CSV file and use a cron job to ship that file to another system.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

rayar
Communicator

and if I want to send in CEF format to the MCAS server
where I define the target server ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Your cron job could invoke a Python script that does the conversion. The target server could be in the script or an external configurable.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

rayar
Communicator

Thanks a lot

0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...