Deployment Architecture

How do you forward Tripwire log messages to Splunk Cloud?

Michael_Carlisl
Explorer

I'm trying to view/send Tripwire logs to my Splunk Cloud instance. There is an option in Tripwire to forward logs to a TCP host and port. I configured this to point to my Splunk instance, but cannot see the logs anywhere. Is there some special repository it goes into to view these logs? Do I need to do something extra (i.e. configure the Splunk forwarder to actually send the log files instead of Tripwire)?

Thanks!
Michael

0 Karma
1 Solution

Michael_Carlisl
Explorer

Michael_Carlisl
Explorer

Ended up just setting the forwarder to pick up the Tripwire syslog...

https://answers.splunk.com/answers/72901/how-to-convert-a-splunk-universal-forwarder-in-intermediary...

Best,
Michael

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...