Alerts for the Splunk Add-on for CyberArk EPM¶
The add-on ships with built-in saved searches that detect operational issues during data collection. All alerts are disabled by default and must be enabled manually.
How to find and enable alerts¶
- In Splunk Web, go to Settings > Searches, reports, and alerts.
- In the App filter, select Splunk Add-on for CyberArk EPM.
- Locate the alert you want to enable and click Edit > Enable.
Built-in alerts¶
CyberArk EPM - API Rate Limit Reached¶
Detects repeated API rate limit or request timeout errors in the add-on’s internal logs.
| Property | Value |
|---|---|
| Schedule | Every 15 minutes |
| Search window | Last 15 minutes |
| Severity | Informational |
| Suppression | 1 hour per input and reason |
Trigger condition: More than 5 rate limit or timeout events for a given input within the search window.
What it reports: Which input is affected, whether the cause is a rate limit or a timeout, and the time range of the first and last occurrence.
What to do: The add-on retries automatically. If the alert fires repeatedly, consider reducing the number of active inputs, increasing the polling interval, or contacting CyberArk Support at support@cyberark.com to raise your API call limit.
Note
This alert covers the Admin Audit Logs, Inbox Events, and Policy Audit Events inputs. The Account Admin Audit Logs input is not included in the alert search scope.