Splunk Search

Any guidance on CyberArk TA v1.2 Installation?

SplunkDash
Motivator

Hello,

I need some guidance to install CyberArk TA in a single-server SPLUNK enterprise environment. How would I proceed with this installation process? Any help will be highly appreciated. Thank you so much.

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

It is required on the search head so please install it there.  It is not used on UFs.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Have you read the instructions?  The docs at https://docs.splunk.com/Documentation/AddOns/released/CyberArk/Installation say there are no special considerations for installing the TA in a distributed environment.  That means the same instructions apply to a single-instance Splunk environment.  There's even a link to single-instance instructions at the bottom of the page.

---
If this reply helps you, Karma would be appreciated.
0 Karma

SplunkDash
Motivator

Hello,

Thank you so much for your reply. I went through before reaching out to SPLUNK community. Now went through in detail. My one question, in the instructions, they mentioned on web form and select Install app from file. Is there any ways I can install the CyberArk TA from the CLI interface. I already downloaded the TA. Any help will be highly appreciated. Thank you.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you can install the TA from the CLI.  Just about any app can be installed that way.

In this case, just expand the downloaded file (it should be a compressed tarball) into the $SPLUNK_HOME/etc/apps directory.  Then restart Splunk.

---
If this reply helps you, Karma would be appreciated.

SplunkDash
Motivator

Hello,

Yes,  I installed and SPLUNK is getting events from that. Is there any documentations on CyberArk TA, I looked at the SPLUNK side, but couldn't find any. Your help will be highly appreciated, thank you! 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The link in my first reply will take you to the complete documentation for the TA.

---
If this reply helps you, Karma would be appreciated.

SplunkDash
Motivator

Hello,

Thank you so much again. That takes me  to the complete documentation for the TA in general. But do we have anything specific on CyberArk TA like any SOP (operational procedure) on it. Thank you!

 

 
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The link (https://docs.splunk.com/Documentation/AddOns/released/CyberArk/Installation) is specific to the CyberArk TA.  That is all the TA-specific documentation I am aware of.

What question are you trying to answer?

---
If this reply helps you, Karma would be appreciated.

SplunkDash
Motivator

Hello,

It says "

Install this add-on to all search heads where CyberArk knowledge management is required.

"

I  installed it on  a machine where UF installed on it. Do I still need to install it on SH, it says it is required. Thank you so much again.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It is required on the search head so please install it there.  It is not used on UFs.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...