Is the Tripwire Enterprise App for Splunk Enterprise compatible with Search head clustering V 6.2.2? If so, does anyone have documentation on how to configure it?
We determined that the Tripwire application needs to reside on the heavy forwarder. This is where you perform the Tripwire application setup. The Tripwire documentation needs to be updated.
The Tripwire Enterprise app runs via a scripted input that in turn requires python. Therefore, the component that retrieves data from the TE console needs to be on either a Heavy Forwarder or a full splunk instance like a Search Head. The python scripted input pulls back data and writes it in CSV format in a flat file, and then a standard Splunk monitor input picks it up. My suggestion to keep things simple, and not have to maintain monitor inputs on all of your search heads in a cluster, is to put the TA portions of the app on a Heavy Forwarder. There is no reason that you can't run the rest of the app on a Search Head Cluster (disable the monitor inputs in the app).
Tripwire Enterprise https://splunkbase.splunk.com/app/1828/
We determined that the Tripwire application needs to reside on the heavy forwarder. This is where you perform the Tripwire application setup. The Tripwire documentation needs to be updated.
Hi @mockuss
When you say "Tripwire application", are you referring to one of these apps from Splunkbase? And if yes, which one?
https://splunkbase.splunk.com/app/1828/
https://splunkbase.splunk.com/app/2682/
I got your clarification @mockuss and edited your post to reflect the proper app and tag. This way, the developer will get a notification that you posted something about their app.
Also, when you get any notification emails for Splunk Answers activity, please don't reply to those emails. You should be responding back here on the post. I only found out about your response because someone forwarded your email to me that was just going to float in limbo 😛