Greetings,
We would like to segregate a couple of our assets and forward their data onto other SIEM instances with our current full Splunk setup. Is it possible to send the same logs on the assets from their respective UFs and HFs to send data to other SIEM solutions instead of Splunk Indexers?
If possible, are there any articles and documentations that specify the detail on how the log is transferred and what steps need to be accomplished in order to achieve the final goal?
Thanks,
Best Regards,
Hi @NightShark,
yes, it's possible, for more infos, please see at :
https://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Forwarddatatothird-partysystemsd
then if you search in Community, you'll find many answers on this topic.
Ciao.
Giuseppe
Thank you
Hi @NightShark,
yes, it's possible, for more infos, please see at :
https://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Forwarddatatothird-partysystemsd
then if you search in Community, you'll find many answers on this topic.
Ciao.
Giuseppe