Getting Data In

Breaking the Cyberark logs

kiran331
Builder

Hi

I'm using TA for CyberArk for onboarding the logs, but i see the the logs are in correct format, how can i break the logs?

log format:

I have to break the log with time field in it.

Jul 15 13:58:47 10.21.29.227 msg=Veri Jul 15 13:54:20Cyber-Ark|Vault|9.60.0000|295|Retrieve password|5|act=Retrieve password suser=PasswordManager fname=Root\Operating System-WinDomain-AD dvc= shost=1.2.3.4 dhost=abc.com duser=ADM externalId= app= reason= cs1Label="Affected User Name" cs1= cs2Label="Safe Name" cs2=XYZ cs3Label="Device Type" cs3=Operating System cs4Label="Database" cs4= cs5Label="Other info" cs5= cn1Label="Request Id" cn1= cn2Label="Ticket Id" cn2=CPM msg=CPMJul 15 13:54:21 CEF:0|Cyber-Ark|Vault|9.60.0000|295|Retrieve password|5|act=Retrieve password suser=PasswordManager fname=Root\Operating System-WinDomainAD dvc= shost=1.3.4.4 dhost=abc.com duser=AD externalId= app= reason= cs1Label="Affected User Name" cs1= cs2Label="Safe Name" cs2=ADM cs3Label="Device Type" cs3=Operating System cs4Label="Database" cs4= cs5Label="Other info" cs5= cn1Label="Request Id" cn1= cn2Label="Ticket Id" cn2=CPM internal process msg=CPM internal processJul 15 13:54:21 dfdf CEF:0|Cyber-Ark|Vault|9.60.0000|295|Retrieve password|5|act=Retrieve password suser=PasswordManager fname=Root dvc= shost=2.3.4. dhost=cba.com duser=_on externalId= app= reason= cs1Label="Affected User Name" cs1= cs2Label="Safe Name" cs2=VaultInternal cs3Label="Device Type" cs3=Operating System cs4Label="Database" cs4= cs5Label="Other info" cs5= cn1Label="Request Id" cn1= cn2Label="Ticket Id" cn2=CPM msg=CPMJul 15 13:54:21 ......

0 Karma

mohammadsharukh
Path Finder

Hi,

Can you please suggest some use cases for Cyberark on Splunk.

0 Karma

javiergn
Super Champion

Hi,

We had exactly the same problem some weeks ago with the CyberArk logs via Syslog.
The format was wrong as CyberArk was meant to be sending individual events and not one big message containing multiple events and breaking the last one because it doesn't fit in a UDP datagram. Check if this is your case and the last event in your message is incomplete.

We told our CyberArk guys and they reported this to the vendor. I think they ended up upgrading to the latest version and the problem is now solved, but I would ask CyberArk in any case.

Thanks,
J

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...