All Apps and Add-ons

Splunk CyberArk and Syslog-NG

cameronr0705
New Member

We're sending CyberArk Vault data to Splunk via a syslog-ng server. We have a number of sources going to the syslog server. CyberArk logs are delayed from writing to the directory by over an hour. The other issue is Splunk_TA_CyberArk doesn't appear to be splitting up the vault log files like it should. CyberArk is running 9.10. Splunk is running 7.0. Any help would be appreciated.

Tags (1)
0 Karma

cameronr0705
New Member

Issue was with the syslog config on Cyberark.

0 Karma

amehta_splunk
Splunk Employee
Splunk Employee
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...