Splunk Cloud Platform

Forward Splunk to MS Sentinel

biers04
Explorer

There at one point was an add-in that was created for sending Splunk logs to MS Sentinel, but appears it was depreciated some time ago. I am in need of incorporating customer data that uses Splunk to my SOC Sentinel environment. Are there any built in functions that can be utilized to forward to Sentinel? The forwarding option in Splunk appears to only work to other Splunk instances. All current add-ins appear to be focused on ingest from Sentinel to Splunk. 

I have been researching a variety of options, but none seem to fill the void that I can find at this time, outside of creating and maintaining my own Splunk add-in.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...

New This Month in Splunk Observability Cloud - Synthetic Monitoring updates, UI ...

This month, we’re delivering several platform, infrastructure, application and digital experience monitoring ...