<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to forward events from Splunk Indexer to CyberArk PTA? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/741576#M117890</link>
    <description>&lt;P&gt;question - why wasn't the data sent directly to the PTA server from the Windows servers via outputs.conf?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Mar 2025 12:43:24 GMT</pubDate>
    <dc:creator>kcooper</dc:creator>
    <dc:date>2025-03-12T12:43:24Z</dc:date>
    <item>
      <title>How to forward events from Splunk Indexer to CyberArk PTA?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/507652#M86399</link>
      <description>&lt;P&gt;Q: Need to forward the data from all the indexes (Windows, Linux, etc...) to CyberArk PTA via Syslog or any other from the Splunk Indexer as we don't have HF in our Environment.&lt;/P&gt;&lt;P&gt;I have followed the documentation given by CyberArk on PTA Splunk Integration,&amp;nbsp;but it is not working (logs are not forwarding to PTA server) for me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Link: &lt;A href="https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/11.2/en/Content/PTA/Configuring-Splunk-Forward-syslog-messages.htm?Highlight=Splunk" target="_blank"&gt;https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/11.2/en/Content/PTA/Configuring-Splunk-Forward-syslog-messages.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Configuration on Indexer:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Emphasis"&gt;SPLUNK_HOME/etc/system/local&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--&amp;gt;outputs.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[syslog:pta_syslog]&lt;BR /&gt;server = &amp;lt;PTA Server IP&amp;gt;:&amp;lt;port&amp;gt;&lt;BR /&gt;indexAndForward=true&lt;BR /&gt;type=tcp&lt;BR /&gt;timestampformat = %s&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;syslogSourceType=sourcetype:: linux:messages&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;----&amp;gt;props.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[source::WinEventLog:Security]&lt;BR /&gt;TRANSFORMS-pta = pta_syslog_filter&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-----&amp;gt;transforms.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[pta_syslog_filter]&lt;BR /&gt;REGEX = .*EventCode=4624|4720|4723|4724|4732.*&lt;BR /&gt;DEST_KEY = _SYSLOG_ROUTING&lt;BR /&gt;FORMAT = pta_syslog&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 07:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/507652#M86399</guid>
      <dc:creator>potnuru</dc:creator>
      <dc:date>2020-07-07T07:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events from Splunk Indexer to CyberArk PTA?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/507653#M86400</link>
      <description>Since we don't have the documentation given by Cyberark, please elaborate on the steps you took to forward data from Splunk Cyberark. What part is failing? What error messages do you get?</description>
      <pubDate>Mon, 06 Jul 2020 18:34:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/507653#M86400</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-06T18:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events from Splunk Indexer to CyberArk PTA?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/507768#M86415</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; I have updated the question with complete details, could you check and help me in finding the resolution.&lt;/P&gt;&lt;P&gt;Basically PTA server is listening (Syslog) on some port let's say 514.&lt;/P&gt;&lt;P&gt;We need to forward all the logs in/coming to Splunk Indexer to PTA Syslog server on some port (514) .&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 07:49:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/507768#M86415</guid>
      <dc:creator>potnuru</dc:creator>
      <dc:date>2020-07-07T07:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events from Splunk Indexer to CyberArk PTA?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/507842#M86423</link>
      <description>I suspect the REGEX line in transforms.conf is to blame. The leading and trailing ".*" are not needed. Have you verified the remainder matches what you want to forward? It won't match Linux logs.</description>
      <pubDate>Tue, 07 Jul 2020 13:34:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/507842#M86423</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-07T13:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events from Splunk Indexer to CyberArk PTA?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/508011#M86451</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;The Regex is working fine and it is applied to only Windows Events Source Type but not other Source Types.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 08:37:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/508011#M86451</guid>
      <dc:creator>potnuru</dc:creator>
      <dc:date>2020-07-08T08:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events from Splunk Indexer to CyberArk PTA?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/519852#M87893</link>
      <description>&lt;P&gt;Is it working for you ?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 08:32:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/519852#M87893</guid>
      <dc:creator>suresh301086</dc:creator>
      <dc:date>2020-09-16T08:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events from Splunk Indexer to CyberArk PTA?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/519853#M87894</link>
      <description>&lt;P&gt;Windows logs are properly parsing where Linu/Unix logs are not parsing to PTA from Splunk&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 08:33:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/519853#M87894</guid>
      <dc:creator>suresh301086</dc:creator>
      <dc:date>2020-09-16T08:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events from Splunk Indexer to CyberArk PTA?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/519880#M87898</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226322"&gt;@suresh301086&lt;/a&gt;&amp;nbsp;By default PTA won't support Linux Events. We need to develop custom plugin on PTA to understand Linux Events.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 10:00:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/519880#M87898</guid>
      <dc:creator>potnuru</dc:creator>
      <dc:date>2020-09-16T10:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events from Splunk Indexer to CyberArk PTA?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/519883#M87899</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226322"&gt;@suresh301086&lt;/a&gt;&amp;nbsp;For me PTA functionality is working for Windows Events and not for Linux Events. Currently we are working on developing custom plugin for Linux Events.&lt;/P&gt;&lt;P&gt;Could you please share your forwarding configuration that you defined on Splunk Indexer/HF?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 10:03:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/519883#M87899</guid>
      <dc:creator>potnuru</dc:creator>
      <dc:date>2020-09-16T10:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events from Splunk Indexer to CyberArk PTA?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/533583#M89607</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/34483"&gt;@potnuru&lt;/a&gt;&amp;nbsp; Could you please explain how did you got those Windows Events to work?&lt;/P&gt;&lt;P&gt;I am having exactly the same problem as you described in your first post - everything is configured per PTA documentation, but Splunk is unable to send messages to PTA.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 16:31:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/533583#M89607</guid>
      <dc:creator>Atavius</dc:creator>
      <dc:date>2020-12-18T16:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events from Splunk Indexer to CyberArk PTA?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/535442#M89803</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229859"&gt;@Atavius&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have followed the CyberArk documentation and it worked for me for Windows Events. Please check the below configuration for your reference.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;#outputs.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[syslog]&lt;/P&gt;&lt;P&gt;defaultGroup = noforward&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[syslog:pta_syslog]&lt;/P&gt;&lt;P&gt;server = PTA-IP:514&lt;/P&gt;&lt;P&gt;type = tcp&lt;/P&gt;&lt;P&gt;timestampformat = %s&lt;/P&gt;&lt;P&gt;syslogSourceType = sourcetype::linux:messages&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;#props.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[source::WinEventLog:Security]&lt;/P&gt;&lt;P&gt;TRANSFORMS-win = pta_syslog_win&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;#transforms.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[pta_syslog_win]&lt;/P&gt;&lt;P&gt;REGEX = .*&amp;lt;your filter&amp;gt;*&lt;/P&gt;&lt;P&gt;DEST_KEY = _SYSLOG_ROUTING&lt;/P&gt;&lt;P&gt;FORMAT = pta_syslog&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 08:15:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/535442#M89803</guid>
      <dc:creator>potnuru</dc:creator>
      <dc:date>2021-01-12T08:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events from Splunk Indexer to CyberArk PTA?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/741576#M117890</link>
      <description>&lt;P&gt;question - why wasn't the data sent directly to the PTA server from the Windows servers via outputs.conf?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 12:43:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-from-Splunk-Indexer-to-CyberArk-PTA/m-p/741576#M117890</guid>
      <dc:creator>kcooper</dc:creator>
      <dc:date>2025-03-12T12:43:24Z</dc:date>
    </item>
  </channel>
</rss>

