Getting Data In

How to forwarded logs from Splunk to MCAS

rayar
Contributor

Hi

What will be the best way to implement the below request ?

We need to configure the some logs to be forwarded from Splunk to MCAS Server (Server in the same network like Splunk server )
Logs should be forwarded in Syslog or FTP and based on a specific query

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

See the docs at https://docs.splunk.com/Documentation/Splunk/8.0.3/Forwarding/Forwarddatatothird-partysystemsd . While some filtering is possible, you cannot forward the results of a query.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

See the docs at https://docs.splunk.com/Documentation/Splunk/8.0.3/Forwarding/Forwarddatatothird-partysystemsd . While some filtering is possible, you cannot forward the results of a query.

---
If this reply helps you, Karma would be appreciated.
0 Karma

rayar
Contributor

Hi
I am getting "Hi! This page does not exist, or has been removed from the Documentation."
so is there another way to send search results to external system ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk didn't like the period at the end of the sentence. Try the revised answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

rayar
Contributor

thanks , I was able to open the doc

so there is no way to sent the results of such query to external system ?

index=websense AND act="Permitted"
| fields _time, suser, src, dst, act, request, in, out
| convert timeformat="%Y-%m-%d %H:%M:%S" ctime(_time) as Time
| table Time, suser, src, dst, act, request, in, out

0 Karma

richgalloway
SplunkTrust
SplunkTrust

No straightforward way. You could schedule a report that saves query results in a CSV file and use a cron job to ship that file to another system.

---
If this reply helps you, Karma would be appreciated.
0 Karma

rayar
Contributor

and if I want to send in CEF format to the MCAS server
where I define the target server ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Your cron job could invoke a Python script that does the conversion. The target server could be in the script or an external configurable.

---
If this reply helps you, Karma would be appreciated.
0 Karma

rayar
Contributor

Thanks a lot

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...