Getting Data In

Splunk HEC events to arcsight

jibin1988
Path Finder

Is it possible to send Splunk HEC events message part to 3rd party collector/arcsight?

Eg... Now it is :

Logstash --- SplunkHEC/ HF --- Indexer

I want to parse message field in the HEC and send to arcsight collector before being send to indexers.

Is it possible?
Kindly help.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...