Yeah more or less. Splunk exposes an HTTP endpoint...
# general
t
Yeah more or less. Splunk exposes an HTTP endpoint that allows you to post events directly to the server, so it'd be similar to if you just POSTed osquery results directly to the ES backing of an ELK stack and bypassed the Logstash/Filebeat steps