Hi, I assume you're inquiring about Guardium Data Protection and alerts from the Data Security Policy to Splunk. The GDP policy alerts are sent to the SYSLOG, so you enable SYSLOG forwarding on each of your Collector appliances by using the store remotelog add cli command.
Below are links to two documentation pages for further assistance:
https://www.ibm.com/docs/en/gdp/12.x?topic=pi-combining-real-time-alerts-correlation-analysis-siem-products
https://www.ibm.com/docs/en/gdp/12.x?topic=commands-configuration-control-cli#concept_dgk_2cj_4lb__store_remotelog
------------------------------
Wendy Zemba
Sr. Consultant, Data Protection
Converge Technology Solutions
wendy.zemba@convergetp.comNeed help with your Guardium deployment? Contact me directly to discuss engagement opportunities. Currently serving North America.
------------------------------