Splunk Cloud Platform

Forward Splunk to MS Sentinel

biers04
Explorer

There at one point was an add-in that was created for sending Splunk logs to MS Sentinel, but appears it was depreciated some time ago. I am in need of incorporating customer data that uses Splunk to my SOC Sentinel environment. Are there any built in functions that can be utilized to forward to Sentinel? The forwarding option in Splunk appears to only work to other Splunk instances. All current add-ins appear to be focused on ingest from Sentinel to Splunk. 

I have been researching a variety of options, but none seem to fill the void that I can find at this time, outside of creating and maintaining my own Splunk add-in.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...