# Logstash with Splunk

**URL:** <https://discuss.elastic.co/t/logstash-with-splunk/38269>\
**Category:** Logstash\
**Created:** [January 3, 2016, 11:57am UTC](https://discuss.elastic.co/t/logstash-with-splunk/38269 "2016-01-03T11:57:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vadimso](https://avatars.discourse-cdn.com/v4/letter/v/9fc29f/32.png) [@vadimso](https://discuss.elastic.co/u/vadimso)\
**Post date:** [January 3, 2016, 11:57am UTC](https://discuss.elastic.co/t/logstash-with-splunk/38269/1 "2016-01-03T11:57:28Z")

</div>

Hello All,  
Is it possible to configure Logstash to send logs (windows event log ) to Splunk to get events after logstash parsing?  
Tnx in advance

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 3, 2016, 9:10pm UTC](https://discuss.elastic.co/t/logstash-with-splunk/38269/2 "2016-01-03T21:10:42Z")

</div>

Logstash can send processed events by a number of means, e.g. raw TCP or UDP, that I'm sure Splunk can monitor. I'd look into [Logstash's list of output plugins](https://www.elastic.co/guide/en/logstash/current/output-plugins.html) and compare it to any similar list of possible inputs that Splunk has and try to find the best match.

Splunk also seems to be capable of reading Windows event logs directly—any reason you want to use Logstash as a middle man?

---

<div class="post-metadata">

**Author:** ![PandKing](https://avatars.discourse-cdn.com/v4/letter/p/258eb7/32.png) [@PandKing](https://discuss.elastic.co/u/PandKing)\
**Post date:** [May 8, 2017, 7:27pm UTC](https://discuss.elastic.co/t/logstash-with-splunk/38269/3 "2017-05-08T19:27:01Z")

</div>

Has anyone else tried to get this working? I have beats going to logstash then ES but for some hosts I also need to send that data to SPLUNK.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:26am UTC](https://discuss.elastic.co/t/logstash-with-splunk/38269/4 "2017-07-06T04:26:43Z")

</div>


