Good morning, I hope you can help me,
we maintain an infrastructure with splunk enterprise with SIEM and we must forward the security events to an elastic and kafka, I would like to know how I could forward the events and if this will consume license.
More words please. What is your business case. What "security events" do you want to "forward" from Splunk. Do you want the same events ingested in Splunk and Elastic/Kafka/whatever or maybe you want to just generate an event in case some alert is triggered in Splunk?
Hola gracias por la respuesta, son eventos de seguridad como eventos de Windows y eventos de equipos perimetrales,
¿necesitamos pasar de elastic para obtener los datos a splunk o reenviar los datos de splunk a elastic, es posible visualizar más datos que el que está indexado? Y si no es posible sería ver mis eventos que se muestran en splunk para verlos en elástico.