I need to get the SiteMinder audit logs into Splunk. Currently they we have them going into an Oracle DB. We want to eliminate the Oracle DB and have the audit logs go directly from SiteMinder into Splunk. Is this possible?
Just to follow up on this if someone else has similar questions. The audit logs can be configured in SiteMinder to write to log on disk rather than to a database. Then it's like another other data input for Splunk.