Splunk Enterprise

connection between elastic and splunk

juanarenas
New Member

Good morning, I hope you can help me,
we maintain an infrastructure with splunk enterprise with SIEM and we must forward the security events to an elastic and kafka, I would like to know how I could forward the events and if this will consume license.

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

More words please. What is your business case. What "security events" do you want to "forward" from Splunk. Do you want the same events ingested in Splunk and Elastic/Kafka/whatever or maybe you want to just generate an event in case some alert is triggered in Splunk?

0 Karma

juanarenas
New Member

Hola gracias por la respuesta, son eventos de seguridad como eventos de Windows y eventos de equipos perimetrales,
¿necesitamos pasar de elastic para obtener los datos a splunk o reenviar los datos de splunk a elastic, es posible visualizar más datos que el que está indexado? Y si no es posible sería ver mis eventos que se muestran en splunk para verlos en elástico.

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...