Skip to content

Alerts for the Splunk Add-on for CyberArk EPM

The add-on ships with built-in saved searches that detect operational issues during data collection. All alerts are disabled by default and must be enabled manually.

How to find and enable alerts

  1. In Splunk Web, go to Settings > Searches, reports, and alerts.
  2. In the App filter, select Splunk Add-on for CyberArk EPM.
  3. Locate the alert you want to enable and click Edit > Enable.

Built-in alerts

CyberArk EPM - API Rate Limit Reached

Detects repeated API rate limit or request timeout errors in the add-on’s internal logs.

Property Value
Schedule Every 15 minutes
Search window Last 15 minutes
Severity Informational
Suppression 1 hour per input and reason

Trigger condition: More than 5 rate limit or timeout events for a given input within the search window.

What it reports: Which input is affected, whether the cause is a rate limit or a timeout, and the time range of the first and last occurrence.

What to do: The add-on retries automatically. If the alert fires repeatedly, consider reducing the number of active inputs, increasing the polling interval, or contacting CyberArk Support at support@cyberark.com to raise your API call limit.

Note

This alert covers the Admin Audit Logs, Inbox Events, and Policy Audit Events inputs. The Account Admin Audit Logs input is not included in the alert search scope.