All Apps and Add-ons

Is the Tripwire Enterprise App for Splunk Enterprise compatible with search head clustering 6.2.2? If so, does anyone have documentation on how to configure it?

mockuss
Explorer

Is the Tripwire Enterprise App for Splunk Enterprise compatible with Search head clustering V 6.2.2? If so, does anyone have documentation on how to configure it?

0 Karma
1 Solution

mockuss
Explorer

We determined that the Tripwire application needs to reside on the heavy forwarder. This is where you perform the Tripwire application setup. The Tripwire documentation needs to be updated.

View solution in original post

0 Karma

jbrodsky_splunk
Splunk Employee
Splunk Employee

The Tripwire Enterprise app runs via a scripted input that in turn requires python. Therefore, the component that retrieves data from the TE console needs to be on either a Heavy Forwarder or a full splunk instance like a Search Head. The python scripted input pulls back data and writes it in CSV format in a flat file, and then a standard Splunk monitor input picks it up. My suggestion to keep things simple, and not have to maintain monitor inputs on all of your search heads in a cluster, is to put the TA portions of the app on a Heavy Forwarder. There is no reason that you can't run the rest of the app on a Search Head Cluster (disable the monitor inputs in the app).

0 Karma

mockuss
Explorer
0 Karma

mockuss
Explorer

We determined that the Tripwire application needs to reside on the heavy forwarder. This is where you perform the Tripwire application setup. The Tripwire documentation needs to be updated.

0 Karma

ppablo
Retired

Hi @mockuss

When you say "Tripwire application", are you referring to one of these apps from Splunkbase? And if yes, which one?
https://splunkbase.splunk.com/app/1828/
https://splunkbase.splunk.com/app/2682/

0 Karma

ppablo
Retired

I got your clarification @mockuss and edited your post to reflect the proper app and tag. This way, the developer will get a notification that you posted something about their app.

Also, when you get any notification emails for Splunk Answers activity, please don't reply to those emails. You should be responding back here on the post. I only found out about your response because someone forwarded your email to me that was just going to float in limbo 😛

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...