Getting Data In

How to ingest Cyberark logs in Splunk?

janclairmont
New Member

Is there a published method or documentation on how to ingest Cyberark logs?

Thanks,
Jan Clairmont
302-669-9972

Tags (1)
0 Karma

rajanala
Path Finder

Can Splunk ingest CyberArk ITA logs also ?

0 Karma

James_wang
Engager

My approach is using CyberArk EVD to export the data into MSSQL (almost no program effort) and then using python to export the log (JSON) which I really want in later analysis. During this period, you can do more correlative process on your data such as binding PolicyID and other customization file category.

The best of this way is that you can save your splunk license and make the log easy to handle, because splunk natively support JSON format log.

The cons: it could only do the near real-time, because EVD only export the data which is about 30 min before.

0 Karma

koshyk
Super Champion

just bumping to see if anyone have implemented TA for Cyberark? Would be very helpful to see how CIM is mapped

0 Karma

michtek
Explorer

Jan, Cyberark offers syslog containing audit events which can be easily fed into Splunk (directly or indirectly). If you just need audit events out of everything that Cyberark is logging, with syslog you won't need a Splunk forwarder installed on any of Cyberark boxes.

Michal

bosburn_splunk
Splunk Employee
Splunk Employee

Jan -

Are cyberark's logs in a text format? I used it at my last job and don't remember if that's the case. If it is, it would be a simple matter of installing a forwarder on the Cyberark server and pointing it at the logs. Then you would have to set up field extractions.

Brian

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...