Splunk Universal forwarder 1-N => Splunk Indexer N => Splunk Search Head 0
I would like to know if i could forward data from Splunk Search Head to a third party software
I know there is apps like CEP.
But i would like to forward data to Splunk Indexer for indexing data aand forward data from Splunk Indexer to Splunk Search Head, and finaly forward data from SplunkSearch Head to a third party software.
I don't want to forward from Splunk Forwarder drectly to third party software.
I would like a single point (Splunk Search Head) to forward to third party software.
May be , i make a mistake with this choice.
What the best practice with a good security to avoid exposing all the Splunk Forwarder or all the Splunk indexer to the third party software.