Join Slack
Powered by
Yeah more or less. Splunk exposes an HTTP endpoint...
# general
t
thor
09/11/2017, 4:43 PM
Yeah more or less. Splunk exposes an HTTP endpoint that allows you to post events directly to the server, so it'd be similar to if you just POSTed osquery results directly to the ES backing of an ELK stack and bypassed the Logstash/Filebeat steps
2
Views
Open in Slack
Previous
Next