Getting Data In

file integrity checking question

kaplan71
New Member

Hi there --

One thought I had of deploying Splunk was the following scenario: Install it on one of our network servers and configuring another one of our servers to forward its log files to the Splunk server. Along with this setup a running of the Tripwire application once a day on the server that is forwarding its log files to the Splunk server.

Would the combination of Splunk and Tripwire be an effective means of file integrity monitoring? More specifically, is Splunk providing an effective file integrity check of the remote server by the latter sending its log files to it?

Thanks.

Tags (1)
0 Karma

JimWachhaus
Path Finder

With the combination of Tripwire Enterprise and Splunk you get the world leading technology for FIM and Security Configuration Management coupled with the power of Splunk for combining event information from multiple sources.

Hot off the presses!

Splunk App for Tripwire Enterprise
http://apps.splunk.com/app/1828/
1.0 version.

0 Karma

treinke
Builder

Why not use the built in file integrity monitor in Splunk? This is set in the inputs.conf file.

Simply add to $SPLUNK_HOME\etc\system\local\inputs.conf:

[fschange:<path to folder/file>]
recurse=true|false
pollPeriod=<time in seconds>

Set recurse to true if you want all subfolders and files.

This will check for add/delete/change of the files at the polling period and report it back to the Splunk server.

More on fschange: http://www.splunk.com/base/Documentation/4.1.4/AppManagement/Configurationmonitoring

There are no answer without questions
Get Updates on the Splunk Community!

How to send events & findings from AWS to Splunk using Amazon EventBridge

Amazon EventBridge is a serverless service that uses events to connect application components together, making ...

Exciting News: The AppDynamics Community Joins Splunk!

Hello Splunkers,   I’d like to introduce myself—I’m Ryan, the former AppDynamics Community Manager, and I’m ...

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...