<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logging tripwire reports in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logging-tripwire-reports/m-p/26605#M4406</link>
    <description>&lt;P&gt;In my setup, I have two machines running Ubuntu Linux. On one, I have Splunk and the other I have running the universal forwarder. Both seem to be working. On the remote box, I run an IDS called Tripwire that stores its logs in a directory /var/lib/tripwire/report. Each report is a separate file in the dir. I added the directory using "add monitor" in the universal forwarder. What I assumed would happen is that newly added files would be logged in Splunk. When I run a tripwire check, the file is created. In Splunk, the only record is that /var/log/messages is updated with a short entry saying that tripwire has been run and the name/timestamp of the newly created file. This is not good enough, as I want to be able to see the entire report from the Splunk server and be able to search those contents (to trigger alerts). Is my understanding of what directory monitoring is Splunk does completely off? I assumed it to send a notification of any additions/changes to files in the monitored directories. Or is my implementation incorrect?&lt;/P&gt;

&lt;P&gt;I also tried another method; since the logging of /var/log/messages worked, I created a /var/trip/tripwire/log where each tripwire report would be appended to. I added that with "add monitor" command, but this hasn't done anything either.  &lt;/P&gt;</description>
    <pubDate>Tue, 06 Aug 2013 20:33:56 GMT</pubDate>
    <dc:creator>Ekrell</dc:creator>
    <dc:date>2013-08-06T20:33:56Z</dc:date>
    <item>
      <title>Logging tripwire reports</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-tripwire-reports/m-p/26605#M4406</link>
      <description>&lt;P&gt;In my setup, I have two machines running Ubuntu Linux. On one, I have Splunk and the other I have running the universal forwarder. Both seem to be working. On the remote box, I run an IDS called Tripwire that stores its logs in a directory /var/lib/tripwire/report. Each report is a separate file in the dir. I added the directory using "add monitor" in the universal forwarder. What I assumed would happen is that newly added files would be logged in Splunk. When I run a tripwire check, the file is created. In Splunk, the only record is that /var/log/messages is updated with a short entry saying that tripwire has been run and the name/timestamp of the newly created file. This is not good enough, as I want to be able to see the entire report from the Splunk server and be able to search those contents (to trigger alerts). Is my understanding of what directory monitoring is Splunk does completely off? I assumed it to send a notification of any additions/changes to files in the monitored directories. Or is my implementation incorrect?&lt;/P&gt;

&lt;P&gt;I also tried another method; since the logging of /var/log/messages worked, I created a /var/trip/tripwire/log where each tripwire report would be appended to. I added that with "add monitor" command, but this hasn't done anything either.  &lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 20:33:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-tripwire-reports/m-p/26605#M4406</guid>
      <dc:creator>Ekrell</dc:creator>
      <dc:date>2013-08-06T20:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Logging tripwire reports</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-tripwire-reports/m-p/26606#M4407</link>
      <description>&lt;P&gt;Your understanding about how file/directory monitor inputs sounds correct to me. When you add a file or directory to be monitored, Splunk will pick up data in that file (or in the case of a directory, any files in that directory or its subdirectories).&lt;/P&gt;

&lt;P&gt;If you're not seeing data from files you've added to be monitored, something is wrong. Could be a permissions issue, could be that the data is really coming in but timestamps are recognized incorrectly so you're just missing it by searching the "wrong" time period. Two things that are very good for troubleshooting inputs:&lt;BR /&gt;
 - Check splunkd.log (in &lt;CODE&gt;$SPLUNK_HOME/var/log/splunk&lt;/CODE&gt;) for errors related to the input.&lt;BR /&gt;
 - Run this script that shows the status of all inputs on the monitoring Splunk instance in question: &lt;A href="http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/"&gt;http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 21:05:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-tripwire-reports/m-p/26606#M4407</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-08-06T21:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Logging tripwire reports</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-tripwire-reports/m-p/26607#M4408</link>
      <description>&lt;P&gt;Have you looked at using Tripwire Enterprise?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2014 16:28:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-tripwire-reports/m-p/26607#M4408</guid>
      <dc:creator>JimWachhaus</dc:creator>
      <dc:date>2014-07-22T16:28:46Z</dc:date>
    </item>
  </channel>
</rss>

