Getting Data In

Splunk integration with other tool

splkadmin
Explorer

Hello 

I am having a single instance of Splunk enterprise on my environment ,Is there a way to forward the Splunk data to other SIEM product on required basis.

Could you please help us to provide the details to procedure on this.

Tags (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @splkadmin,

You can see options sending data to third parties on below document.

https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd

 

If this reply helps you an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

0 Karma

scelikok
SplunkTrust
SplunkTrust

Universal Forwarders can send data only to another Splunk instances. You should setup outputs.conf only on indexers or heavy forwarders to forward data to third party. You can select data by using host, source, sourcetype or regex based on data contents.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

splkadmin
Explorer

Thank you for your reply ..

Ok I have single instance of Splunk  enterprise and installed a universal forwarder on all the client.

Now I have to sent data to third party SIEM systems..

Should I configure only output.conf or just add the forwarded IP on Splunk instance console ?

do we able to configure a props.conf and transforms.conf on same instance? or do I require heavy forwarder to do that.

 

0 Karma

scelikok
SplunkTrust
SplunkTrust

You can use single-instance Splunk Enterprise to forward data using methods/samples provided in the document. You do not need to have a heavy forwarder.

You need to configure outputs.conf and also props.conf, transforms.conf in order to route data.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @splkadmin,

You can see options sending data to third parties on below document.

https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd

 

If this reply helps you an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

splkadmin
Explorer

In that case do we need to add the output.conf  on each client server that i have installed a universal forwarder or should I add only to the Splunk enterprise instance that suppose to forward the all client logs to the third party server.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...