CyberArk Privilege Access Management for Microsoft Sentinel

Solution: CyberArk Privilege Access Manager (PAM) Events

CyberArk Privilege Access Manager (PAM) Events Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher Cyberark
Support Tier Partner
Support Link https://www.cyberark.com/services-support/technical-support/
Categories domains
Version 3.0.3
Author Cyberark
First Published 2022-05-02
Solution Folder CyberArk Enterprise Password Vault (EPV) Events
Marketplace Azure Marketplace · Popularity: 🔵 Medium (67%)
Pre-requisites Common Event Format

CyberArk Enterprise Password Vault Solution for Microsoft Sentinel enables ingestion of Common Event Format (CEF) logs into Microsoft Sentinel. The EPV generates an xml Syslog message for every action taken against the Vault. The EPV will send the xml messages through the Sentinel.xsl translator to be converted into CEF standard format and sent to a syslog server of your choice (syslog-ng, rsyslog). The Log Analytics agent installed on your syslog staging server will import the messages into Azure Log Analytics. Refer to the CyberArk documentation for more guidance on SIEM integrations.

This solution is dependent on the Common Event Format solution containing the CEF via AMA connector to collect the logs. The CEF solution will be installed as part of this solution installation.

NOTE: Microsoft recommends installation of CEF via AMA Connector. The existing connectors were deprecated on Aug 31, 2024.

Contents

Pre-requisites

This solution depends on 1 other solution(s):

Solution
Common Event Format

Data Connectors

This solution has 2 discovered data connector(s)⚠️ (not in Solution definition):

Connectors from dependency solutions:

🔍 Discovered: This item was discovered by scanning the solution folder but is not listed in the Solution JSON file.

Tables Used

This solution uses 1 table(s):

Table Used By Connectors Used By Content
CommonSecurityLog Common Event Format (CEF) (dependency), Common Event Format (CEF) via AMA (dependency), [Deprecated] CyberArk Enterprise Password Vault (EPV) Events via Legacy Agent, [Deprecated] CyberArk Privilege Access Manager (PAM) Events via AMA Workbooks

Content Items

This solution includes 1 content item(s):

Content Type Count
Workbooks 1

Workbooks

Name Tables Used
CyberArkEPV CommonSecurityLog

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index