Deployment Architecture

How do you forward Tripwire log messages to Splunk Cloud?

Michael_Carlisl
Explorer

I'm trying to view/send Tripwire logs to my Splunk Cloud instance. There is an option in Tripwire to forward logs to a TCP host and port. I configured this to point to my Splunk instance, but cannot see the logs anywhere. Is there some special repository it goes into to view these logs? Do I need to do something extra (i.e. configure the Splunk forwarder to actually send the log files instead of Tripwire)?

Thanks!
Michael

0 Karma
1 Solution

Michael_Carlisl
Explorer

Michael_Carlisl
Explorer

Ended up just setting the forwarder to pick up the Tripwire syslog...

https://answers.splunk.com/answers/72901/how-to-convert-a-splunk-universal-forwarder-in-intermediary...

Best,
Michael

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...