Tripwire Enterprise App for Splunk Enterprise has add-on that go on forwarders. The doc only mentions heavy forwarders. Can the add-on be put on universal forwarders?
You will need a heavy forwarder to run the python scripts that extract the FIM and SCM data.
The universal forwarder will work for the TCP syslog...a subset of the data collected.