Splunk Search

Any guidance on CyberArk TA v1.2 Installation?

SplunkDash
Motivator

Hello,

I need some guidance to install CyberArk TA in a single-server SPLUNK enterprise environment. How would I proceed with this installation process? Any help will be highly appreciated. Thank you so much.

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

It is required on the search head so please install it there.  It is not used on UFs.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Have you read the instructions?  The docs at https://docs.splunk.com/Documentation/AddOns/released/CyberArk/Installation say there are no special considerations for installing the TA in a distributed environment.  That means the same instructions apply to a single-instance Splunk environment.  There's even a link to single-instance instructions at the bottom of the page.

---
If this reply helps you, Karma would be appreciated.
0 Karma

SplunkDash
Motivator

Hello,

Thank you so much for your reply. I went through before reaching out to SPLUNK community. Now went through in detail. My one question, in the instructions, they mentioned on web form and select Install app from file. Is there any ways I can install the CyberArk TA from the CLI interface. I already downloaded the TA. Any help will be highly appreciated. Thank you.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you can install the TA from the CLI.  Just about any app can be installed that way.

In this case, just expand the downloaded file (it should be a compressed tarball) into the $SPLUNK_HOME/etc/apps directory.  Then restart Splunk.

---
If this reply helps you, Karma would be appreciated.

SplunkDash
Motivator

Hello,

Yes,  I installed and SPLUNK is getting events from that. Is there any documentations on CyberArk TA, I looked at the SPLUNK side, but couldn't find any. Your help will be highly appreciated, thank you! 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The link in my first reply will take you to the complete documentation for the TA.

---
If this reply helps you, Karma would be appreciated.

SplunkDash
Motivator

Hello,

Thank you so much again. That takes me  to the complete documentation for the TA in general. But do we have anything specific on CyberArk TA like any SOP (operational procedure) on it. Thank you!

 

 
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The link (https://docs.splunk.com/Documentation/AddOns/released/CyberArk/Installation) is specific to the CyberArk TA.  That is all the TA-specific documentation I am aware of.

What question are you trying to answer?

---
If this reply helps you, Karma would be appreciated.

SplunkDash
Motivator

Hello,

It says "

Install this add-on to all search heads where CyberArk knowledge management is required.

"

I  installed it on  a machine where UF installed on it. Do I still need to install it on SH, it says it is required. Thank you so much again.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It is required on the search head so please install it there.  It is not used on UFs.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...