Hi
I am new to splunk and have a doubt.I have some logs in which transformation has to be done for changing the format of the log.After transformation I need to store these logs in another host.Will this be possible in splunk? if so,how to do it?
Hi Jananee_iNautix
welcome to Splunk 🙂
Take a look at this page on docs it is all about forwarding data from Splunk to third party systems.
Update: by following this docs, you will 'convert' your Splunk indexer into a heavy forwarder. One Splunk instance can be indexer and forwarder at the same time.
Hope this helps to get you started ...
cheers, MuS