Getting Data In

file integrity checking question

kaplan71
New Member

Hi there --

One thought I had of deploying Splunk was the following scenario: Install it on one of our network servers and configuring another one of our servers to forward its log files to the Splunk server. Along with this setup a running of the Tripwire application once a day on the server that is forwarding its log files to the Splunk server.

Would the combination of Splunk and Tripwire be an effective means of file integrity monitoring? More specifically, is Splunk providing an effective file integrity check of the remote server by the latter sending its log files to it?

Thanks.

Tags (1)
0 Karma

JimWachhaus
Path Finder

With the combination of Tripwire Enterprise and Splunk you get the world leading technology for FIM and Security Configuration Management coupled with the power of Splunk for combining event information from multiple sources.

Hot off the presses!

Splunk App for Tripwire Enterprise
http://apps.splunk.com/app/1828/
1.0 version.

0 Karma

treinke
Builder

Why not use the built in file integrity monitor in Splunk? This is set in the inputs.conf file.

Simply add to $SPLUNK_HOME\etc\system\local\inputs.conf:

[fschange:<path to folder/file>]
recurse=true|false
pollPeriod=<time in seconds>

Set recurse to true if you want all subfolders and files.

This will check for add/delete/change of the files at the polling period and report it back to the Splunk server.

More on fschange: http://www.splunk.com/base/Documentation/4.1.4/AppManagement/Configurationmonitoring

There are no answer without questions
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI &#43; Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...