If you are not using a Search Head Cluster, but instead are using individual Search Heads, you can do it like this:
https://answers.splunk.com/answers/514258/search-heads-authentication-credentials-rejected-b.html#answer-514306
... View more
Since the cyberark application can only log syslog data, configure syslog to send the data to a syslog receiver and using a heavy forwarder, push the logs to splunk. this is the most effective way of implementing this solution.
... View more