All Apps and Add-ons

Why does the Tripwire Enterprise App for Splunk Enterprise stop collecting data after a few days?

addproniklas
Engager

Hi

I've been trying to set up the Tripwire App for a few months now, but run in to the exact same problem every time.

The issue I have is that the event collection stops and the tripwire_fim.py gets started in multiple instances. It seems that after a while, the python script freezes in its connection with the Tripwire server and waits forever.

The current work around is that I need to kill all instances of the script and also restart the Tripwire server. Then it works for a few days and the issue is there all over again.

I've been in contact with Tripwire support, they can't help me since this is a Splunk App (Even if the app is downloaded from their website)
I've been doing some tests with the Tripwire SOAP API with the twtool after issue has occurred (twtool is a special tool where you can interact with tripwire thru CLI), so far the tests has been successful, indicating that there is some problem with the Splunk app. But since there is no logging function in the app, I can't see what is the reason for the app to stop working.

Is there anyone that has encountered this problem?
Hopefully someone can help me with this, perhaps the developer of this app has got some more insights in what could be the problem?

Best Regards

0 Karma

JimWachhaus
Path Finder

What version of the app are you using? The current version is 1.5.4

What you are describing is not typical behavior.

It may be helpful to look at the Tripwire Enterprise logs to see if the app is opening multiple connections.

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...