Splunk Search

Any guidance on CyberArk TA v1.2 Installation?

SplunkDash
Motivator

Hello,

I need some guidance to install CyberArk TA in a single-server SPLUNK enterprise environment. How would I proceed with this installation process? Any help will be highly appreciated. Thank you so much.

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

It is required on the search head so please install it there.  It is not used on UFs.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Have you read the instructions?  The docs at https://docs.splunk.com/Documentation/AddOns/released/CyberArk/Installation say there are no special considerations for installing the TA in a distributed environment.  That means the same instructions apply to a single-instance Splunk environment.  There's even a link to single-instance instructions at the bottom of the page.

---
If this reply helps you, Karma would be appreciated.
0 Karma

SplunkDash
Motivator

Hello,

Thank you so much for your reply. I went through before reaching out to SPLUNK community. Now went through in detail. My one question, in the instructions, they mentioned on web form and select Install app from file. Is there any ways I can install the CyberArk TA from the CLI interface. I already downloaded the TA. Any help will be highly appreciated. Thank you.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you can install the TA from the CLI.  Just about any app can be installed that way.

In this case, just expand the downloaded file (it should be a compressed tarball) into the $SPLUNK_HOME/etc/apps directory.  Then restart Splunk.

---
If this reply helps you, Karma would be appreciated.

SplunkDash
Motivator

Hello,

Yes,  I installed and SPLUNK is getting events from that. Is there any documentations on CyberArk TA, I looked at the SPLUNK side, but couldn't find any. Your help will be highly appreciated, thank you! 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The link in my first reply will take you to the complete documentation for the TA.

---
If this reply helps you, Karma would be appreciated.

SplunkDash
Motivator

Hello,

Thank you so much again. That takes me  to the complete documentation for the TA in general. But do we have anything specific on CyberArk TA like any SOP (operational procedure) on it. Thank you!

 

 
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The link (https://docs.splunk.com/Documentation/AddOns/released/CyberArk/Installation) is specific to the CyberArk TA.  That is all the TA-specific documentation I am aware of.

What question are you trying to answer?

---
If this reply helps you, Karma would be appreciated.

SplunkDash
Motivator

Hello,

It says "

Install this add-on to all search heads where CyberArk knowledge management is required.

"

I  installed it on  a machine where UF installed on it. Do I still need to install it on SH, it says it is required. Thank you so much again.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It is required on the search head so please install it there.  It is not used on UFs.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...