<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to ingest Cyberark logs in Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126379#M97727</link>
    <description>&lt;P&gt;just bumping to see if anyone have implemented TA for Cyberark?  Would be very helpful to see how CIM is mapped&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jul 2015 11:21:13 GMT</pubDate>
    <dc:creator>koshyk</dc:creator>
    <dc:date>2015-07-28T11:21:13Z</dc:date>
    <item>
      <title>How to ingest Cyberark logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126376#M97724</link>
      <description>&lt;P&gt;Is there a published method or documentation on how to ingest Cyberark logs?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Jan Clairmont&lt;BR /&gt;
302-669-9972&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2014 14:12:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126376#M97724</guid>
      <dc:creator>janclairmont</dc:creator>
      <dc:date>2014-07-01T14:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest Cyberark logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126377#M97725</link>
      <description>&lt;P&gt;Jan -&lt;/P&gt;

&lt;P&gt;Are cyberark's logs in a text format?  I used it at my last job and don't remember if that's the case.  If it is, it would be a simple matter of installing a forwarder on the Cyberark server and pointing it at the logs.  Then you would have to set up field extractions.&lt;/P&gt;

&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2014 02:47:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126377#M97725</guid>
      <dc:creator>bosburn_splunk</dc:creator>
      <dc:date>2014-07-02T02:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest Cyberark logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126378#M97726</link>
      <description>&lt;P&gt;Jan, Cyberark offers syslog containing audit events which can be easily fed into Splunk (directly or indirectly). If you just need audit events out of everything that Cyberark is logging, with syslog you won't need a Splunk forwarder installed on any of Cyberark boxes.&lt;/P&gt;

&lt;P&gt;Michal&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2014 23:23:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126378#M97726</guid>
      <dc:creator>michtek</dc:creator>
      <dc:date>2014-07-08T23:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest Cyberark logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126379#M97727</link>
      <description>&lt;P&gt;just bumping to see if anyone have implemented TA for Cyberark?  Would be very helpful to see how CIM is mapped&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2015 11:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126379#M97727</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2015-07-28T11:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest Cyberark logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126380#M97728</link>
      <description>&lt;P&gt;My approach is using CyberArk EVD to export the data into MSSQL (almost no program effort) and then using python to export the log (JSON) which I really want in later analysis. During this period, you can do more correlative process on your data such as binding PolicyID and other customization file category.&lt;/P&gt;

&lt;P&gt;The best of this way is that you can save your splunk license and make the log easy to handle, because splunk natively support JSON format log.&lt;/P&gt;

&lt;P&gt;The cons: it could only do the near real-time, because EVD only export the data which is about 30 min before.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 02:02:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126380#M97728</guid>
      <dc:creator>James_wang</dc:creator>
      <dc:date>2016-12-22T02:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest Cyberark logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126381#M97729</link>
      <description>&lt;P&gt;Can Splunk ingest CyberArk ITA logs also ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 16:05:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Cyberark-logs-in-Splunk/m-p/126381#M97729</guid>
      <dc:creator>rajanala</dc:creator>
      <dc:date>2019-06-11T16:05:18Z</dc:date>
    </item>
  </channel>
</rss>

