Centrify, a recognized worldwide leader in Identity-Centric Privileged Access Management solutions, offers its customers seamless integration with Splunk Enterprise Security. Through the Centrify Add-On for Splunk, customers who leverage Splunk to monitor, search, analyze, and visualize IT machine-generated data can now enrich that data with Centrify-specific events.
The Centrify Add-On for Splunk categorizes event log data captured from the Centrify Platform related to privileged access activity and normalizes these events for the Splunk Common Information Model (CIM). This allows real-time analysis and risk mitigation to identify a potential breach in progress.
Key Features:
· Minimize the risk associated with privileged access abuse.
· Centralize visibility across enterprise deployments.
· Easily import categorized data sets from privileged user activity.
· Leverage existing investments in SIEM and alert tools without additional costs.