Splunk Search

CEF output to Arcsight - where can I find 'rtoutput.py' ?

meno
Path Finder

Where can I find rtoutput.py ? It is mentioned here on page 8.

Tags (1)
0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

The framework is still being tightly controlled while it undergoes additional development - specifically, I am working on a UI for it 🙂

I will be sure to upload to Splunkbase and post a blog when it is ready for mass distribution.

View solution in original post

araitz
Splunk Employee
Splunk Employee

The framework is still being tightly controlled while it undergoes additional development - specifically, I am working on a UI for it 🙂

I will be sure to upload to Splunkbase and post a blog when it is ready for mass distribution.

matthieu_araman
Communicator

it looks like this rtoutput.py script is no longer needed -> the functionality is now integrated into splunk cef app which allow most configuration via a web form.

0 Karma

awurster
Contributor

can we have an update on this please? is it part of the real time output app?

http://splunk-base.splunk.com/apps/48082/splunk-real-time-output

0 Karma

edbolton
Explorer

I'm very interested in doing this in my environment, has there been any movement on the UI/formal support?

0 Karma

dmlee
Communicator

Hi araitz,

our customer also want to use splunk to monitor logs and send alert message to ArcSight, May I know the progress of your framework ? Could you please share rtoutput.py to us ? thank you.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...