Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | CyberArkEPMCCPDefinition |
| Publisher | CyberArk |
| Used in Solutions | CyberArkEPM |
| Collection Method | CCF |
| Connector Definition Files | mainTemplate.json |
| Ingestion API | Log Ingestion API — Sibling ARM template declares DCR / Log Ingestion API resources |
| Microsoft Learn | View on Learn |
The CyberArk Endpoint Privilege Manager data connector enables Microsoft Sentinel to ingest security event logs and other events from CyberArk EPM via REST API.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
CyberArk_EPMEvents_CL |
✗ | ✓ | ✗ |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Connect to CyberArk EPM API to start collecting event logs in Microsoft Sentinel
Follow the configuration steps here to integrate Microsoft Sentinel with CyberArk EPM and enable centralized monitoring of endpoint events within Microsoft Sentinel.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊