Hey Everyone,
i got information if Wazuh can send data to Splunk, i want reverse it.
Because i want to send data from Splunk to Wazuh, in my case because i have TI who have API that can be send data to Splunk, then i want forward it to Wazuh.
Maybe if using third party like Logstash / Elastic / etc ?
Did anyone know about it? because i never read about it before..
Thanks
If I remember correctly, Wazuh is based on OpenSearch. So you need to configure syslog input(s) on Wazuh's side and syslog export on your HF(s) and/or indexer(s) (depending on your particular architecture and ingestion process).
Thanks for your reply, i will try that before. If success i'll be back to Accept it as Solution so another people who have the same problem can use this step.
Hi @zksvc ,
I never used Wazuh, but I can suppose that it's like other third party systems, so you can see at:
https://docs.splunk.com/Documentation/SplunkCloud/latest/Search/Forwarddatatothirdpartysystems
https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd
Ciao.
Giuseppe
Thanks for your reply, i will try that before. If success i'll be back to Accept it as Solution so another people who have the same problem can use this step.
Danke,
Zake