Hi Splunkers,
I have a doubt about Slunk data forwarding to third part systems.
I know that this task can be performed with forwarders; what I'm not able to understand is if it can be performed after data are arrived to Splunk and has been ingested, parsed and aggregated.
let me explain better: in a usual scenario, we know that Forwarder are something that stay before a Splunk environment, so it is something similar to:
Data sources -> Forwarders (on DS or on intermediate) -> Splunk environment (SH +Indexer)
With Forwarder I can achieve this scenario:
Data sources -> Forwarders (on DS or on intermediate) -> Splunk environment (SH +Indexer)
-> Other systems
So, I can forward data before they arrive to SH + Indexer.
But what about if I need to perform this task:
Data sources -> Forwarders (on DS or on intermediate) -> Splunk environment (SH +Indexer) -> parsing, aggregation and filtering -> Forwarding to third part system
Is it possible? The requirement is that data must have completed all Splunk lifecycle: they arrive raw/only partially manipulated from Mulesoft, then must be parsed, filtered and aggregated and after this sent back to Mulesoft that forward them to final systems.
Is this something that I can achieve with Splunk?
Splunk will only forward raw data to third-party systems. See https://docs.splunk.com/Documentation/Splunk/9.0.1/Forwarding/Forwarddatatothird-partysystemsd
Splunk will only forward raw data to third-party systems. See https://docs.splunk.com/Documentation/Splunk/9.0.1/Forwarding/Forwarddatatothird-partysystemsd