I'm trying to view/send Tripwire logs to my Splunk Cloud instance. There is an option in Tripwire to forward logs to a TCP host and port. I configured this to point to my Splunk instance, but cannot see the logs anywhere. Is there some special repository it goes into to view these logs? Do I need to do something extra (i.e. configure the Splunk forwarder to actually send the log files instead of Tripwire)?
Thanks!
Michael
Ended up just setting the forwarder to pick up the Tripwire syslog...
Best,
Michael
Ended up just setting the forwarder to pick up the Tripwire syslog...
Best,
Michael