I was thinking of using the add-on for CyberArk to change logs' format from CyberArki PTA into CEF format input to Splunk Enterprise.
Splunk Add-on for CyberArk | Splunkbase
However, as the link above shows, it seems the latest version of the add-on support PTA 12.2, and there is no updates on this add-on.
Anyone knows about the version interoperability of PTA version 14.2 and this add-on? Or, is there are alternatives for this add-on?
I really apprecitate any comment. Thank you.
##Splunk-Add-on-for-CyberAr
@Meett Hello, thank you for your kind reply. I am glad to hear that you know the case that plug-in is used with v14.2. I'll be researching more and find what to do next.
Hello @gomitamu ,
CyberArk TA supports only CyberArk v12. Official support for v14 is not available at this time. However you can use same TA to get data and twick the props if needed, i have seen some people using this TA with v14 and is working fine for them.
Hello @gomitamu ,
CyberArk TA supports only CyberArk v12. Official support for v14 is not available at this time. However you can use same TA to get data and twick the props if needed, i have seen some people using this TA with v14 and is working fine for them.