Splunk Enterprise Security

Spunk App for CEF format not detecting on CyberArk PTA

arjunhunurkar
New Member

Hello,

Splunk App for CEF is installed on Splunk HF, I did all the field mapping to the Log which is required for CyberArk PTA to detect.
but not sure why it isn't detecting?

earlier before spunk, we use to have Arcsight and the logs were used to come in CEF format and CyberArk PTA used to detect.

Now, having Splunk App for CEF which means logs are coming in CEF format as similar to Arcsight CEF format logs but don't know the reason why CyberArk PTA is not detecting.
Taken this issue with CyberArk, even they doesn't know.

Can anyone help here please?

Regards,
Arjun

0 Karma

harsmarvania57
Ultra Champion

Can you please explain, what you are trying to achieve ? If you want to send Windows/Linux Authentication logs from Splunk to PTA then follow this doc https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PTA/Configuring-Splunk-Forwar...

0 Karma

arjunhunurkar
New Member

@harsmarvania57 , mate appreciate your effort. I have already built PTA with splunk and was working fine but here the situation is different now. here is the below flow:
Target Machine(snare) ->LogCollector->File->SplunkUF->SplunkHF(splunk App for CEF)->PTA
now the logs are coming in CEF format.

can you tell me how to create time field which will give me time value in epoch format?

Regards,
Arjun

0 Karma

harsmarvania57
Ultra Champion

When data is flowing from SplunkHF -> PTA, why are you converting it into CEF format ?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...