Getting Data In

Read and transfer data from splunk index to other application

Explorer

I would like to know if there is a way to read from splunk DB and redirect that data to some other application. I have splunk server configured on linux and lightweight forwaders installed on windows to collect Eventlogs. i would like to read Eventdata from splunk and transfer to some other application.

Tags (2)

SplunkTrust
SplunkTrust

You can use the Splunk CLI to run a search from a script, and then do as you wish with the result data from that search. A better approach might be to let splunk proactively forward data to this 3rd party system via TCP socket or syslog.

See http://www.splunk.com/base/Documentation/latest/Admin/Forwarddatatothird-partysystems