Getting Data In

Using HFs and UFs to send logs to other SIEM

NightShark
Path Finder

Greetings,

We would like to segregate a couple of our assets and forward their data onto other SIEM instances with our current full Splunk setup. Is it possible to send the same logs on the assets from their respective UFs and HFs to send data to other SIEM solutions instead of Splunk Indexers?

If possible, are there any articles and documentations that specify the detail on how the log is transferred and what steps need to be accomplished in order to achieve the final goal?

Thanks,

Best Regards,

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

NightShark
Path Finder

Thank you

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @NightShark,

yes, it's possible, for more infos, please see at :

https://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Forwarddatatothird-partysystemsd

https://docs.splunk.com/Documentation/Splunk/8.2.5/Forwarding/Routeandfilterdatad#Replicate_a_subset...

then if you search in Community, you'll find many answers on this topic.

Ciao.

Giuseppe

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...