How can I setup Splunk to ingest CaPAM (Computer Associates - Privilege Access Management) data directly?