Hello,
Splunk App for CEF is installed on Splunk HF, I did all the field mapping to the Log which is required for CyberArk PTA to detect.
but not sure why it isn't detecting?
earlier before spunk, we use to have Arcsight and the logs were used to come in CEF format and CyberArk PTA used to detect.
Now, having Splunk App for CEF which means logs are coming in CEF format as similar to Arcsight CEF format logs but don't know the reason why CyberArk PTA is not detecting.
Taken this issue with CyberArk, even they doesn't know.
Can anyone help here please?
Regards,
Arjun
Can you please explain, what you are trying to achieve ? If you want to send Windows/Linux Authentication logs from Splunk to PTA then follow this doc https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PTA/Configuring-Splunk-Forwar...
@harsmarvania57 , mate appreciate your effort. I have already built PTA with splunk and was working fine but here the situation is different now. here is the below flow:
Target Machine(snare) ->LogCollector->File->SplunkUF->SplunkHF(splunk App for CEF)->PTA
now the logs are coming in CEF format.
can you tell me how to create time field which will give me time value in epoch format?
Regards,
Arjun
When data is flowing from SplunkHF -> PTA, why are you converting it into CEF format ?