Splunk Enterprise Security

Spunk App for CEF format not detecting on CyberArk PTA

arjunhunurkar
New Member

Hello,

Splunk App for CEF is installed on Splunk HF, I did all the field mapping to the Log which is required for CyberArk PTA to detect.
but not sure why it isn't detecting?

earlier before spunk, we use to have Arcsight and the logs were used to come in CEF format and CyberArk PTA used to detect.

Now, having Splunk App for CEF which means logs are coming in CEF format as similar to Arcsight CEF format logs but don't know the reason why CyberArk PTA is not detecting.
Taken this issue with CyberArk, even they doesn't know.

Can anyone help here please?

Regards,
Arjun

0 Karma

harsmarvania57
SplunkTrust
SplunkTrust

Can you please explain, what you are trying to achieve ? If you want to send Windows/Linux Authentication logs from Splunk to PTA then follow this doc https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PTA/Configuring-Splunk-Forwar...

0 Karma

arjunhunurkar
New Member

@harsmarvania57 , mate appreciate your effort. I have already built PTA with splunk and was working fine but here the situation is different now. here is the below flow:
Target Machine(snare) ->LogCollector->File->SplunkUF->SplunkHF(splunk App for CEF)->PTA
now the logs are coming in CEF format.

can you tell me how to create time field which will give me time value in epoch format?

Regards,
Arjun

0 Karma

harsmarvania57
SplunkTrust
SplunkTrust

When data is flowing from SplunkHF -> PTA, why are you converting it into CEF format ?

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!