We are currently using SFG to transfer files, sending fie movement and info data to DB tables, and then using Splunk Heavy Forwarder to query the DB, and then sending to indexes from there.
I would like to trim that process. Has anyone ingested SFG data events into Splunk more directly? i.e. via API or some other more direct process?
Thanks for your thoughts.
Bill
Any solution found? We are getting involved into the topic as well. Wonder if anyone have found a solution already ?
Me too looking for the same