Thank you @stefanmaerz! That's some great input, much appreciated!Regarding
. Does that mean all logs first goes to Fleet and are then forwarded to Splunk? That seems like a nice thing since that would mean only that one machine would need to be able to reach Splunk.
02/12/2019, 6:37 PM
Correct. Logs get collected on the fleet server. Fleet server ships them to Splunk.In my envioronment if I just used osquery, the alternative would have been either install a Splunk forwarder on every endpoint or log locally and ship to syslog.
02/12/2019, 6:54 PM
Thank you again @stefanmaerz, that's very helpful!