Getting Data In

UF to indexer and forward specific sourcetype to third-party siem

_biri_
New Member

Hi, from a customer I have this type, UF with Security events that sends them to a Splunk indexer. I would like to forward these events (only Security ad Application) to a third-party siem.
I tried the configuration found on this post posts but I can't forward these events correctly.

https://answers.splunk.com/answers/400161/how-to-forward-sourcetype-from-a-heavy-forwarder-t.html

https://answers.splunk.com/answers/448100/is-it-possible-to-index-and-forward-a-specific-sou.html

https://docs.splunk.com/Documentation/Splunk/6.4.3/Forwarding/Routeandfilterdatad#Replicate_a_subset...

Does anyone have a working configuration?

0 Karma
Get Updates on the Splunk Community!

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...

New Customer Testimonials

Enterprises of all sizes and across different industries are accelerating cloud adoption by migrating ...