- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to parse the Splunk Add-on for CyberArk logs in the correct format?
kiran331
Builder
08-10-2017
12:50 PM
Hi
I installed the Splunk add-on for CyberArk and configured as per the documentation, but the logs don't seem to be parsing. Each event will be around 30-50 lines and I don't see the CIM fields in logs. Does it work on 6.6 with CIM 4.7?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

mhouse3
Path Finder
08-10-2017
01:54 PM
Try setting UseLegacySyslogFormat=No in the dbparm.ini to send the priority of the SYSLOG to Splunk, and then add this in the props.conf for line breaking for multiline events that are sent from the vault.
If this does not help see:
https://docs.splunk.com/Documentation/AddOns/released/CyberArk/Configureinputs
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gizemk00
Engager
08-24-2017
11:43 PM
Hi mhouse3,
We changed UseLegacySyslogFormat as No and then log size not changed. How do we add the changed dbparm to the props.conf? as text or whatelse??
