<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Beyondtrust Remote support integration to splunk cloud in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyondtrust-Remote-support-integration-to-splunk-cloud/m-p/679289#M2868</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tried to integrate beyontrust privileged remote support app integration to splunk for gettting the logs from BT PRA as per the documentation beyondtrust.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.beyondtrust.com/docs/remote-support/how-to/integrations/splunk/configure-splunk.htm" target="_blank"&gt;https://www.beyondtrust.com/docs/remote-support/how-to/integrations/splunk/configure-splunk.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Documentation has some 4-5 steps to configure in data inputs&lt;/P&gt;&lt;P&gt;1.Input name .&lt;/P&gt;&lt;P&gt;2.Client ID &amp;amp; token received from the beyond trust post once they enable the api.&lt;/P&gt;&lt;P&gt;3.PRA site id.&lt;/P&gt;&lt;P&gt;5.index name&lt;/P&gt;&lt;P&gt;6.source type&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have provided these details but we are unable to see the logs coming to Splunk. However, when check in index=_internal able to beyondtrust config logs in Splunk but not the actual event logs from beyond trust pra.&lt;/P&gt;&lt;P&gt;Could you please kindly let me know if anyone has integrated BT PRA and if any troubleshooting steps/guidance to confirm that there is issue from Splunk side so that. will ask the BT team to further check from there end.&lt;/P&gt;&lt;P&gt;This app is&amp;nbsp; not Splunk developed.no support from Splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you &amp;amp; much appreciated for your responses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2024 14:55:54 GMT</pubDate>
    <dc:creator>tv00638481</dc:creator>
    <dc:date>2024-03-01T14:55:54Z</dc:date>
    <item>
      <title>Beyondtrust Remote support integration to splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyondtrust-Remote-support-integration-to-splunk-cloud/m-p/679289#M2868</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tried to integrate beyontrust privileged remote support app integration to splunk for gettting the logs from BT PRA as per the documentation beyondtrust.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.beyondtrust.com/docs/remote-support/how-to/integrations/splunk/configure-splunk.htm" target="_blank"&gt;https://www.beyondtrust.com/docs/remote-support/how-to/integrations/splunk/configure-splunk.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Documentation has some 4-5 steps to configure in data inputs&lt;/P&gt;&lt;P&gt;1.Input name .&lt;/P&gt;&lt;P&gt;2.Client ID &amp;amp; token received from the beyond trust post once they enable the api.&lt;/P&gt;&lt;P&gt;3.PRA site id.&lt;/P&gt;&lt;P&gt;5.index name&lt;/P&gt;&lt;P&gt;6.source type&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have provided these details but we are unable to see the logs coming to Splunk. However, when check in index=_internal able to beyondtrust config logs in Splunk but not the actual event logs from beyond trust pra.&lt;/P&gt;&lt;P&gt;Could you please kindly let me know if anyone has integrated BT PRA and if any troubleshooting steps/guidance to confirm that there is issue from Splunk side so that. will ask the BT team to further check from there end.&lt;/P&gt;&lt;P&gt;This app is&amp;nbsp; not Splunk developed.no support from Splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you &amp;amp; much appreciated for your responses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 14:55:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyondtrust-Remote-support-integration-to-splunk-cloud/m-p/679289#M2868</guid>
      <dc:creator>tv00638481</dc:creator>
      <dc:date>2024-03-01T14:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Beyondtrust Remote support integration to splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyondtrust-Remote-support-integration-to-splunk-cloud/m-p/695124#M3177</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262528"&gt;@tv00638481&lt;/a&gt;&amp;nbsp;- Have you got any fix for this issue. I too facing the same. PRA logs not getting updated into splunk.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 19:05:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyondtrust-Remote-support-integration-to-splunk-cloud/m-p/695124#M3177</guid>
      <dc:creator>krish_splunk_99</dc:creator>
      <dc:date>2024-08-02T19:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Beyondtrust Remote support integration to splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyondtrust-Remote-support-integration-to-splunk-cloud/m-p/709075#M3478</link>
      <description>&lt;P&gt;Yes, i'm also facing similar issue. not resolved.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 12:26:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Beyondtrust-Remote-support-integration-to-splunk-cloud/m-p/709075#M3478</guid>
      <dc:creator>tv00638481</dc:creator>
      <dc:date>2025-01-17T12:26:58Z</dc:date>
    </item>
  </channel>
</rss>

