Getting Data In

Splunk integration to Wazuh

zksvc
Contributor

Hey Everyone, 

i got information if Wazuh can send data to Splunk, i want reverse it. 

Because i want to send data from Splunk to Wazuh, in my case because i have TI who have API that can be send data to Splunk, then i want forward it to Wazuh. 

Maybe if using third party like Logstash / Elastic / etc ? 

Did anyone know about it? because i never read about it before.. 

Thanks

 

Wazuh-To-Splunk.png

0 Karma

PickleRick
SplunkTrust
SplunkTrust

If I remember correctly, Wazuh is based on OpenSearch. So you need to configure syslog input(s) on Wazuh's side and syslog export on your HF(s) and/or indexer(s) (depending on your particular architecture and ingestion process).

zksvc
Contributor

Thanks for your reply, i will try that before. If success i'll be back to Accept it as Solution so another people who have the same problem can use this step.

0 Karma

gcusello
SplunkTrust
SplunkTrust

zksvc
Contributor

Thanks for your reply, i will try that before. If success i'll be back to Accept it as Solution so another people who have the same problem can use this step.

Danke, 

Zake

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...