Monitoring Splunk

Splunk vs Tripwire

okonswn
New Member

Hey, can someone help me?

i'm new to the IT and have absolutly no knowledge about those kind of stuff but i have to find out about the monitoring features of Tripwire and Splunk.

Can someone help me here and fill this Excel with y/n in the Splunk part and if possible add more feature that Splunk have but Tripewire not?

 

FeaturesTripwireSplunk
Agent-based log collectionyes 
Logs deliverd over encrypted connection with compressionyes 
Resiliency when disconnected from management consoleyes 
Offline data collection when disconnected from consoleyes 
Extensive platform supportyes 
Remote log collectionyes 
Support for multi-line log file collectionyes 
Preservation of original log contentyes 
High compression ratio for storageyes 
Ability to store logs centrallyyes 
Ability to store logs locallyyes 
Ability to encrypt stored log datayes 
Separation of logs by locationyes 
Role-based access to log datayes 
Scheduled archiving of logsyes 
Search functionality available via REST APIyes 
Indexed logs für fast searchingyes 
Industry standard classification of events for fast searchingyes 
Simultaneous, multiple results windows for comparing query outputyes 
Scheduled reportsyes 
lain text and REGEX searchesyes 
Visual custom rule builderyes 
Extensive fields available for correlationyes 
Pre-built correlation rules to detect events of interest or sequences of eventsyes 
Pre-built correlation rules for compliance requirementsyes 
Correlation with non-log data sourcesyes 
Integration with security configuration management tools like Tripwire Enterprise for asset tag datayes 
Dynamic correlation listsyes 
Integration with Active Directory for dynamic user listsyes 
Correlation Engine rules can execute custom scripts as an actionyes 
Correlation Engine can store events in an accessible databaseyes 
Log forwarding to multiple destinationsyes 
Event forwarding from correlation rulesyes 
Scheduled reporting tasksyes 
Pre-built and customizable dashboardsyes 
Correlation Engine rules can generate E-mailsyes 
Correlation Engine rules can generate syslog eventsyes 
Correlation Engine rules can generate console notificationsyes 
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...