Getting Data In

file integrity checking question

kaplan71
New Member

Hi there --

One thought I had of deploying Splunk was the following scenario: Install it on one of our network servers and configuring another one of our servers to forward its log files to the Splunk server. Along with this setup a running of the Tripwire application once a day on the server that is forwarding its log files to the Splunk server.

Would the combination of Splunk and Tripwire be an effective means of file integrity monitoring? More specifically, is Splunk providing an effective file integrity check of the remote server by the latter sending its log files to it?

Thanks.

Tags (1)
0 Karma

JimWachhaus
Path Finder

With the combination of Tripwire Enterprise and Splunk you get the world leading technology for FIM and Security Configuration Management coupled with the power of Splunk for combining event information from multiple sources.

Hot off the presses!

Splunk App for Tripwire Enterprise
http://apps.splunk.com/app/1828/
1.0 version.

0 Karma

treinke
Builder

Why not use the built in file integrity monitor in Splunk? This is set in the inputs.conf file.

Simply add to $SPLUNK_HOME\etc\system\local\inputs.conf:

[fschange:<path to folder/file>]
recurse=true|false
pollPeriod=<time in seconds>

Set recurse to true if you want all subfolders and files.

This will check for add/delete/change of the files at the polling period and report it back to the Splunk server.

More on fschange: http://www.splunk.com/base/Documentation/4.1.4/AppManagement/Configurationmonitoring

There are no answer without questions
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...