All Apps and Add-ons

Bomgar or BeyondTrust Remote Support logs into splunk

pmac22
Path Finder

Hey all,

I already know that beyondtrust has a paid splunk app to get more info like session details into splunk but the demo I saw was specifically referencing Privileged Remote Access and not necessarily Remote Support. Plus the demo was a crap-show with the engineer not even knowing how to navigate the app in Splunk. Anyway, they have the ability to create an outbound event via HTTP or XML APIs. Has anyone created an API for extracting bomgar/beyondtrust session details into Splunk or have suggestions outside of their paid app? Or have suggestions on how to ingest HTTP data in Splunk in a way so I can isolate the Remote Support data to the HTTP event collector on my indexer? Thank you in advance!!

Tags (1)
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...