Hello,
Splunk App for CEF is installed on Splunk HF, I did all the field mapping to the Log which is required for CyberArk PTA to detect.
but not sure why it isn't detecting?
earlier before spunk, we use to have Arcsight and the logs were used to come in CEF format and CyberArk PTA used to detect.
Now, having Splunk App for CEF which means logs are coming in CEF format as similar to Arcsight CEF format logs but don't know the reason why CyberArk PTA is not detecting.
Taken this issue with CyberArk, even they doesn't know.
Can anyone help here please?
Regards,
Arjun
... View more