Getting Data In

file integrity checking question

kaplan71
New Member

Hi there --

One thought I had of deploying Splunk was the following scenario: Install it on one of our network servers and configuring another one of our servers to forward its log files to the Splunk server. Along with this setup a running of the Tripwire application once a day on the server that is forwarding its log files to the Splunk server.

Would the combination of Splunk and Tripwire be an effective means of file integrity monitoring? More specifically, is Splunk providing an effective file integrity check of the remote server by the latter sending its log files to it?

Thanks.

Tags (1)
0 Karma

JimWachhaus
Path Finder

With the combination of Tripwire Enterprise and Splunk you get the world leading technology for FIM and Security Configuration Management coupled with the power of Splunk for combining event information from multiple sources.

Hot off the presses!

Splunk App for Tripwire Enterprise
http://apps.splunk.com/app/1828/
1.0 version.

0 Karma

treinke
Builder

Why not use the built in file integrity monitor in Splunk? This is set in the inputs.conf file.

Simply add to $SPLUNK_HOME\etc\system\local\inputs.conf:

[fschange:<path to folder/file>]
recurse=true|false
pollPeriod=<time in seconds>

Set recurse to true if you want all subfolders and files.

This will check for add/delete/change of the files at the polling period and report it back to the Splunk server.

More on fschange: http://www.splunk.com/base/Documentation/4.1.4/AppManagement/Configurationmonitoring

There are no answer without questions
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...