All Apps and Add-ons

Is the Tripwire Enterprise App for Splunk Enterprise compatible with search head clustering 6.2.2? If so, does anyone have documentation on how to configure it?

mockuss
Explorer

Is the Tripwire Enterprise App for Splunk Enterprise compatible with Search head clustering V 6.2.2? If so, does anyone have documentation on how to configure it?

0 Karma
1 Solution

mockuss
Explorer

We determined that the Tripwire application needs to reside on the heavy forwarder. This is where you perform the Tripwire application setup. The Tripwire documentation needs to be updated.

View solution in original post

0 Karma

jbrodsky_splunk
Splunk Employee
Splunk Employee

The Tripwire Enterprise app runs via a scripted input that in turn requires python. Therefore, the component that retrieves data from the TE console needs to be on either a Heavy Forwarder or a full splunk instance like a Search Head. The python scripted input pulls back data and writes it in CSV format in a flat file, and then a standard Splunk monitor input picks it up. My suggestion to keep things simple, and not have to maintain monitor inputs on all of your search heads in a cluster, is to put the TA portions of the app on a Heavy Forwarder. There is no reason that you can't run the rest of the app on a Search Head Cluster (disable the monitor inputs in the app).

0 Karma

mockuss
Explorer
0 Karma

mockuss
Explorer

We determined that the Tripwire application needs to reside on the heavy forwarder. This is where you perform the Tripwire application setup. The Tripwire documentation needs to be updated.

View solution in original post

0 Karma

ppablo
Community Manager
Community Manager

Hi @mockuss

When you say "Tripwire application", are you referring to one of these apps from Splunkbase? And if yes, which one?
https://splunkbase.splunk.com/app/1828/
https://splunkbase.splunk.com/app/2682/

0 Karma

ppablo
Community Manager
Community Manager

I got your clarification @mockuss and edited your post to reflect the proper app and tag. This way, the developer will get a notification that you posted something about their app.

Also, when you get any notification emails for Splunk Answers activity, please don't reply to those emails. You should be responding back here on the post. I only found out about your response because someone forwarded your email to me that was just going to float in limbo 😛

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!