<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CyberArk Audit for Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742723#M117983</link>
    <description>&lt;P&gt;I have no idea what they mean by "certificate" and "private key" since the fields are just text fields (and neither splunkbase page nor Cyberark's docs help here). But when you type anything in and click save, you'll get to the "add input" dialog, where you can type in stuff like API endpoint or region.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Mar 2025 14:43:46 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2025-03-26T14:43:46Z</dc:date>
    <item>
      <title>CyberArk Audit for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742722#M117982</link>
      <description>&lt;P&gt;Is there any documentation on creating an input for this app? (&lt;A href="https://splunkbase.splunk.com/app/6608" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/6608&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;I installed the app.&lt;/P&gt;&lt;P&gt;Upon launching, it's asking for certificate and private key.&lt;/P&gt;&lt;P&gt;There is no place for me to configure the API endpoint.&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 14:17:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742722#M117982</guid>
      <dc:creator>vh</dc:creator>
      <dc:date>2025-03-26T14:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: CyberArk Audit for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742723#M117983</link>
      <description>&lt;P&gt;I have no idea what they mean by "certificate" and "private key" since the fields are just text fields (and neither splunkbase page nor Cyberark's docs help here). But when you type anything in and click save, you'll get to the "add input" dialog, where you can type in stuff like API endpoint or region.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 14:43:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742723#M117983</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-03-26T14:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: CyberArk Audit for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742728#M117984</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235441"&gt;@vh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I’ve set up this add-on in my lab environment and can see the data input option listed below. Could you please take a look and confirm?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Navigate to Settings &amp;gt; Data Inputs.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1743003219402.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38344iB52597E0604F8A10/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1743003219402.png" alt="kiran_panchavat_0-1743003219402.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1743003320375.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38345i2E8A891263E332DC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1743003320375.png" alt="kiran_panchavat_0-1743003320375.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Multiple CyberArk data inputs.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1743003380801.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38346i169C52F87583AF77/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1743003380801.png" alt="kiran_panchavat_0-1743003380801.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 15:36:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742728#M117984</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-26T15:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: CyberArk Audit for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742739#M117985</link>
      <description>&lt;P class=""&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235441"&gt;@vh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class=""&gt;It took some work, but I finally got this addon up and running.&lt;BR /&gt;On the addon's setup screen, you need to paste the contents of the certificate and the private key generated in the CyberArk console.&lt;/P&gt;&lt;P class=""&gt;The certificate and private key contents are in the following format:&lt;BR /&gt;-----BEGIN%20CERTIFICATE-----xxxxxxxxxxxxxxxxxx-----END%20CERTIFICATE-----%0A&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;To generate the necessary information in the CyberArk console, follow the procedure available at the following link:&lt;/STRONG&gt;&lt;BR /&gt;&lt;A class="" href="https://docs.cyberark.com/admin-space/latest/en/content/siem-integration/siem-export-splunk.htm" target="_new" rel="noopener"&gt;https://docs.cyberark.com/admin-space/latest/en/content/siem-integration/siem-export-splunk.htm&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;After the setup, you can create the input at &lt;STRONG&gt;Settings &amp;gt; Data Input &amp;gt; CyberArk Audit for Splunk&lt;/STRONG&gt;, filling in the fields with the data generated in the CyberArk console.&lt;/P&gt;&lt;P class=""&gt;You can monitor the addon's operation through the logs available at:&lt;BR /&gt;index=_internal source="*splunkd.log" cyberark&lt;/P&gt;&lt;P class=""&gt;If you need to redo the addon's setup, you can do so by clicking the &lt;STRONG&gt;"Setup"&lt;/STRONG&gt; link under &lt;STRONG&gt;Apps &amp;gt; Manage Apps&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 18:35:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742739#M117985</guid>
      <dc:creator>luizlimapg</dc:creator>
      <dc:date>2025-03-26T18:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: CyberArk Audit for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742829#M118007</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/267805"&gt;@luizlimapg&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thank you for the response.&lt;/P&gt;&lt;P&gt;Upon launching the app for the first time, I got prompted to enter the cert and private key, which I did.&lt;/P&gt;&lt;P&gt;After this process, it is supposed to take me to an input page so I can fill in the rest of the information generated on the CyberArk side.&lt;/P&gt;&lt;P&gt;However, the Input page is showing a 404 Error stead.&lt;/P&gt;&lt;P&gt;I have removed and reinstalled this app a few times with no success.&lt;/P&gt;&lt;P&gt;The server I'm having this issue is running Splunk Enterprise version 9.3.2.&lt;/P&gt;&lt;P&gt;I installed this app on an older version of Splunk Enterprise, version 9.2.3, and got the expected inputs screen.&lt;/P&gt;&lt;P&gt;So, I'm wondering if it's a versioning info.&lt;/P&gt;&lt;P&gt;I don't want to downgrade Splunk Enterprise to test this.&lt;/P&gt;&lt;P&gt;I plan to upgrade the problematic server to 9.4.1 later anyway (for other reasons too.)&lt;/P&gt;&lt;P&gt;Any more thoughts on this?&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 15:20:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742829#M118007</guid>
      <dc:creator>vh</dc:creator>
      <dc:date>2025-03-27T15:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: CyberArk Audit for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742831#M118008</link>
      <description>&lt;P&gt;Yes, that's the expected behavior.&lt;/P&gt;&lt;P&gt;Instead, after entering the cert and key info, I'm redirected to a 404 error page (where it's supposed to display the input page.)&lt;/P&gt;&lt;P&gt;thanks for the response.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 15:22:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742831#M118008</guid>
      <dc:creator>vh</dc:creator>
      <dc:date>2025-03-27T15:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: CyberArk Audit for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742857#M118013</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235441"&gt;@vh&lt;/a&gt;,&lt;/P&gt;&lt;P class=""&gt;Quite strange behavior. Here I'm using version 1.0.23 of the add-on and 9.2.4 of Splunk Enterprise.&lt;/P&gt;&lt;P class=""&gt;You could try installing an earlier version of the add-on, it might work.&lt;BR /&gt;On Splunkbase, the last version that supports only Splunk Enterprise is 1.0.24, that's a good version to try&lt;/P&gt;&lt;P class=""&gt;As a last resort, you could have only the heavy forwarder running version 9.2.3 of Splunk with the add-on installed. It would work, but it's not ideal.&lt;/P&gt;&lt;P class=""&gt;Let me know if it works&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 16:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/742857#M118013</guid>
      <dc:creator>luizlimapg</dc:creator>
      <dc:date>2025-03-27T16:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: CyberArk Audit for Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/757069#M120093</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I also working on similar integration, and I have a question regarding CIM Normalization. There is a existing CyberArk addon available for On prem CyberArk CEF format logs. However, using this CyberArk Audit addon we will receive logs in JSON and I don't see any Splunk addon can help with normalization. Can you please tell me how did you manage to parse the logs?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2026 16:41:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CyberArk-Audit-for-Splunk/m-p/757069#M120093</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2026-01-08T16:41:14Z</dc:date>
    </item>
  </channel>
</rss>

