<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How would I configure CyberArk TA, Search Head, and Syslog Server? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611414#M212586</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as you can read in the link you shared:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;The Splunk Add-on for CyberArk allows a Splunk software administrator to pull system logs and traffic statistics from Privileged Threat Analytics (PTA) 12.2 and Enterprise Password Vault (EPV) 12.2 using syslog in Common Event Format (CEF). This add-on extracts CyberArk real-time privileged account activities (such as individual user activity when using shared accounts) into the Splunk platform and Splunk Enterprise Security, providing a single place to analyze unusual account activity.&lt;/LI-CODE&gt;&lt;P&gt;using this TA you have both EPV and PTA logs in CEF format.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 31 Aug 2022 06:16:10 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-08-31T06:16:10Z</dc:date>
    <item>
      <title>How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611204#M212520</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Data in CyberArk comes through the Syslog Server and CyberArk TA needs to be installed into Search head (or search head cluster) based on the SPLUNK web site &lt;SPAN&gt;(&lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/CyberArk/Installation" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.splunk.com/Documentation/AddOns/released/CyberArk/Installation&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;. I installed this TA directly into the Syslog server, but not working as expected. How I would configure, Syslog, SHC, and CyberArk? Any help would be highly appreciated. Thank you!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 20:27:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611204#M212520</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-08-29T20:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611247#M212535</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As described in documentation, this TA must be installed in all Search Heads (clustered or not) because there are some parsing actions made at search time.&lt;/P&gt;&lt;P&gt;In addition, there are some parsing actions made at index time, for this reason it must be also installed on the first Heavy Forwarders (if present) between the syslog server and Indexers.&lt;/P&gt;&lt;P&gt;If there isn't any HF (syslogs are taken by an Universal Forwarder that send them to Indexers), it must be installed on Indexers.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 07:32:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611247#M212535</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-30T07:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611385#M212571</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have one more question on CyberArk TA.&lt;/P&gt;&lt;P&gt;We typically have 2 types of CyberArk logs PTA and EPV, but the CyberArk TA we have,&amp;nbsp; has only one source type &lt;STRONG&gt;cyberark.pta:cef&lt;/STRONG&gt;. It means that CyberArk TA is associated with only PTA logs. My question is, if this is the case we won't need to have EPV logs? Your thoughts and recommendation will be highly appreciated. Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 22:26:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611385#M212571</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-08-30T22:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611414#M212586</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as you can read in the link you shared:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;The Splunk Add-on for CyberArk allows a Splunk software administrator to pull system logs and traffic statistics from Privileged Threat Analytics (PTA) 12.2 and Enterprise Password Vault (EPV) 12.2 using syslog in Common Event Format (CEF). This add-on extracts CyberArk real-time privileged account activities (such as individual user activity when using shared accounts) into the Splunk platform and Splunk Enterprise Security, providing a single place to analyze unusual account activity.&lt;/LI-CODE&gt;&lt;P&gt;using this TA you have both EPV and PTA logs in CEF format.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 06:16:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611414#M212586</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-31T06:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611447#M212593</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you so much for detail clarifications. I have 2 more questions, do these PTA and EPV events coming under&amp;nbsp;&lt;STRONG&gt;cyberark.pta:cef&amp;nbsp; &lt;/STRONG&gt;source type, I just see one source type in CyberArk TA? and what is the latest version for CyberArk TA? Thank you again and appreciate your support in these efforts.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 12:54:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611447#M212593</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-08-31T12:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611461#M212595</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;yes: using the &lt;STRONG&gt;cyberark.pta:cef&amp;nbsp;&lt;/STRONG&gt;sourcetype you have both&amp;nbsp;&lt;SPAN&gt;PTA and EPV events.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can find the latest version of this TA (1.2.0) at &lt;A href="https://splunkbase.splunk.com/app/2891/" target="_blank"&gt;https://splunkbase.splunk.com/app/2891/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 13:48:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611461#M212595</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-31T13:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611462#M212596</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is extra ordinarily helpful, much appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 13:50:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611462#M212596</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-08-31T13:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611638#M212638</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I have a few use cases to send data from SPLUNK to consumers in real time, and consumers have both Linux/Windows OS. Does SPLUNK has any options to do that? Or how would I do it? I also posted this question. But, sending you here, just wanted to make sure you have it. Any help will be highly appreciated. Thank you so much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 16:16:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611638#M212638</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-09-01T16:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611703#M212664</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this is a new and different question, so I hint to create a new question, in this way you'll surely have a quicker and probably better answer from more people of Community.&lt;/P&gt;&lt;P&gt;Anyway, what do you mea with "&lt;SPAN&gt;send data from SPLUNK to consumers in real time"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if you mean forwarding all (or a part of) events via syslog or to anothe Splunk, it's possible, could you better describe your request?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 06:47:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/611703#M212664</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-02T06:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/613538#M213237</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&lt;/P&gt;&lt;P&gt;On CyberArk TA,&amp;nbsp; we are getting data through syslog servers where UFs (no HFs there) installed on them, so data is in syslog servers. Based on your recommendations, I am planning to Install this TA on SH and Indexer clusters. We also have deployment servers with HFs installed on them and syslog servers are also be used&amp;nbsp; as Deployment Clients. Should I also need to install this TA on Deployment Servers as well? Thank you so much for your support in these efforts, truly appreciate it.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 22:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/613538#M213237</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-09-18T22:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/613555#M213242</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you don't need to install any app or Add-On of the Deployment Server for itself,&lt;/P&gt;&lt;P&gt;if you have to deploy apps to UFs or HFs you have to use the DS to deploy these apps: so you have to copy the apps to deploy in $SPLUNK_HOME/etc/deployment-apps,&lt;/P&gt;&lt;P&gt;but you don't need to install on it.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 06:33:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/613555#M213242</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-19T06:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/613578#M213247</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for your quick response. Just a quick question, installation apps in SHC and Indexer cluster meant unzip the &lt;STRONG&gt;.tgz&lt;/STRONG&gt; file and copy/transfer the unzip&amp;nbsp; files there, right?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 10:23:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/613578#M213247</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-09-19T10:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/613586#M213251</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;to install an App in SHC, you have to copy it in the $SPLUNK_HOME/etc/shcluster of the Deployer and deploy&amp;nbsp; it following the instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/DistSearch/PropagateSHCconfigurationchanges" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/DistSearch/PropagateSHCconfigurationchanges&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For indexer Cluester,&amp;nbsp;, you have to copy it in the $SPLUNK_HOME/etc/master-apps of the master Node and deploy&amp;nbsp; it following the instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Indexer/Updatepeerconfigurations" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Indexer/Updatepeerconfigurations&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In few words, you have to untar the Apps in the above folders and then run a command by CLi or by GUI.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 11:12:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/613586#M213251</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-19T11:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: How would I configure CyberArk TA, Search Head, and Syslog Server?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/613592#M213254</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I uploaded one more question in SPLUNK community page&amp;nbsp; with tittle&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;"How would I assign 1 sourcetype 2 different indexes?"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I would appreciate your feedback/recommendation&amp;nbsp;when you have a chance, Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 11:59:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-configure-CyberArk-TA-Search-Head-and-Syslog-Server/m-p/613592#M213254</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-09-19T11:59:01Z</dc:date>
    </item>
  </channel>
</rss>

