All Apps and Add-ons

Is the Tripwire Enterprise App for Splunk Enterprise compatible with search head clustering 6.2.2? If so, does anyone have documentation on how to configure it?

mockuss
Explorer

Is the Tripwire Enterprise App for Splunk Enterprise compatible with Search head clustering V 6.2.2? If so, does anyone have documentation on how to configure it?

0 Karma
1 Solution

mockuss
Explorer

We determined that the Tripwire application needs to reside on the heavy forwarder. This is where you perform the Tripwire application setup. The Tripwire documentation needs to be updated.

View solution in original post

0 Karma

jbrodsky_splunk
Splunk Employee
Splunk Employee

The Tripwire Enterprise app runs via a scripted input that in turn requires python. Therefore, the component that retrieves data from the TE console needs to be on either a Heavy Forwarder or a full splunk instance like a Search Head. The python scripted input pulls back data and writes it in CSV format in a flat file, and then a standard Splunk monitor input picks it up. My suggestion to keep things simple, and not have to maintain monitor inputs on all of your search heads in a cluster, is to put the TA portions of the app on a Heavy Forwarder. There is no reason that you can't run the rest of the app on a Search Head Cluster (disable the monitor inputs in the app).

0 Karma

mockuss
Explorer
0 Karma

mockuss
Explorer

We determined that the Tripwire application needs to reside on the heavy forwarder. This is where you perform the Tripwire application setup. The Tripwire documentation needs to be updated.

0 Karma

ppablo
Retired

Hi @mockuss

When you say "Tripwire application", are you referring to one of these apps from Splunkbase? And if yes, which one?
https://splunkbase.splunk.com/app/1828/
https://splunkbase.splunk.com/app/2682/

0 Karma

ppablo
Retired

I got your clarification @mockuss and edited your post to reflect the proper app and tag. This way, the developer will get a notification that you posted something about their app.

Also, when you get any notification emails for Splunk Answers activity, please don't reply to those emails. You should be responding back here on the post. I only found out about your response because someone forwarded your email to me that was just going to float in limbo 😛

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...