All Apps and Add-ons

Splunk CyberArk and Syslog-NG

cameronr0705
New Member

We're sending CyberArk Vault data to Splunk via a syslog-ng server. We have a number of sources going to the syslog server. CyberArk logs are delayed from writing to the directory by over an hour. The other issue is Splunk_TA_CyberArk doesn't appear to be splitting up the vault log files like it should. CyberArk is running 9.10. Splunk is running 7.0. Any help would be appreciated.

Tags (1)
0 Karma

cameronr0705
New Member

Issue was with the syslog config on Cyberark.

0 Karma

amehta_splunk
Splunk Employee
Splunk Employee
0 Karma
Get Updates on the Splunk Community!

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

[Coming Soon] Splunk Observability Cloud - Enhanced navigation with a modern look and ...

We are excited to introduce our enhanced UI that brings together AppDynamics and Splunk Observability. This is ...