Splunk Cloud Platform

Extract information from an index by consuming the Rest API

JoseLuisZM
Observer

Hi team

Is there a way to connect the splunk cloud platform with splunk on-prem, this to send a specific index to splunk on-prem?

Since the client does not allow modifications to the universal forwarder agents.

 

Regards

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

You can use the API to perform normal searches. Theoretically, you could retrieve indexed events and reingest them on the receiving side. But that is far far from convenient and can cause loads of problems.

0 Karma

JoseLuisZM
Observer

And if the client does not accept any type of configuration, is it possible to extract the information or events using Splunk's APIs?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

I cannot see an option how this can do without any configuration on onprem side.

Usually clients approve some configuration changes if they really want this and when those options have explained to them.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If needed you could add suitable props.conf + transforms.conf on indexers or if you have intermediate HF before on prem indexers to do this. I said that better to have separate HFs before indexers and if possible use those only with those UFs which contains data for this index.

Currently you could also use federated search to search those events on SCP even those are stored in on prem. 
Based on your use case you could chose between those options.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...