Splunk Search

Is it possible to consume data from Splunk by another system?

rakeshyv0807
Explorer

Hello,

Currently we are doing a POC where we are forwarding data to Splunk cloud via HTTP Event collector. We are also using Splunk cloud where the data from several systems is being forwarded to splunk cloud via Heavy & Universal Forwarders. We came across a requirement where we need to push the data that is collected in splunk to a third party system by any means. We want to first try with the POC we are doing and later implement the same in our actual environment. Can you please suggest if something like this possible and if so how to achieve it?

Any help is greatly appreciated and thanks in advance.

Rakesh

Tags (1)
0 Karma

adonio
Ultra Champion

read here all the way through the article:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Forwarding/Forwarddatatothird-partysystemsd

note: not sure what are the capabilities of moving data from Splunk Cloud, therefore ill reccomend to first try focus your POC on instances under your control such as Heavy Forwarders

hope it helps

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...