Getting Data In

file integrity checking question

kaplan71
New Member

Hi there --

One thought I had of deploying Splunk was the following scenario: Install it on one of our network servers and configuring another one of our servers to forward its log files to the Splunk server. Along with this setup a running of the Tripwire application once a day on the server that is forwarding its log files to the Splunk server.

Would the combination of Splunk and Tripwire be an effective means of file integrity monitoring? More specifically, is Splunk providing an effective file integrity check of the remote server by the latter sending its log files to it?

Thanks.

Tags (1)
0 Karma

JimWachhaus
Path Finder

With the combination of Tripwire Enterprise and Splunk you get the world leading technology for FIM and Security Configuration Management coupled with the power of Splunk for combining event information from multiple sources.

Hot off the presses!

Splunk App for Tripwire Enterprise
http://apps.splunk.com/app/1828/
1.0 version.

0 Karma

treinke
Builder

Why not use the built in file integrity monitor in Splunk? This is set in the inputs.conf file.

Simply add to $SPLUNK_HOME\etc\system\local\inputs.conf:

[fschange:<path to folder/file>]
recurse=true|false
pollPeriod=<time in seconds>

Set recurse to true if you want all subfolders and files.

This will check for add/delete/change of the files at the polling period and report it back to the Splunk server.

More on fschange: http://www.splunk.com/base/Documentation/4.1.4/AppManagement/Configurationmonitoring

There are no answer without questions
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...