Forward data to third-party systems

Splunk software can forward data to third-party systems as follows:

  • Through a plain TCP socket
  • Packaged in a standard syslog

To forward data to third-party systems, you configure heavy forwarders by editing the outputs.conf, props.conf and transforms.conf files. This export method is similar to routing your data to other Splunk deployments. You can filter the data by host, source, or source type.

See Forward data to third party systems in the Forwarding Data manual.