Release notes for the Splunk Add-on for CyberArk EPM¶
Version 5.0.1 of the Splunk Add-on for CyberArk EPM was released on
About this release¶
Version 5.0.1 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.
| Component | Description |
|---|---|
| Splunk platform versions | 9.2, 9.3, 9.4, 10.0, 10.1, 10.2, 10.3, 10.4, 10.5, 10.6 |
| CIM | 8.6.0 |
| Platforms | Platform independent |
| Vendor Products | CyberArk Endpoint Privilege Manager v24.12.1, v25.6.1, v26.4, v26.5.0, v26.5.1, v26.6.0, v26.7.0, v26.7.1, v26.8.2 |
Upgrade notes¶
- API Logout events for the
cyberark:epm:admin:auditsourcetype now use the CIM-prescribedaction="logoff"value instead ofaction="logout". Update saved searches, dashboards, and alerts that filter on the old value. - The
cyberark_epm_account_admin_audit_logs_account_changesevent type no longer mapscyberark:epm:account:admin:auditevents to Change.Account_Management solely becauseDescriptionbegins withAPI Logout. Events withFeature="Account Mgmt"remain mapped. To find all Account Admin Audit API Logout events directly, usesourcetype="cyberark:epm:account:admin:audit" Description="API Logout*". - These event type changes affect the accelerated Change data model. Splunk software automatically rebuilds an accelerated data model when a referenced event type changes and Automatic Rebuilds is enabled. If Automatic Rebuilds is disabled for the Change data model, rebuild it manually from the Data Model Manager. Searches that use the acceleration summary can return stale results until the rebuild finishes.
Fixed issues¶
Version 5.0.1 of the Splunk Add-on for CyberArk EPM has the following fixed issues. If no issues appear in this section, no issues have yet been reported:
- The add-on no longer forces EPM REST API version
25.6.1in supported API URLs. The EPM server selects its latest available API version, while the Computer Groups endpoint continues to use its documentedv2path. Account validation also provides more actionable messages for HTTP 401, 403, and 404 responses without exposing credentials or tokens. - Account Admin Audit collection now rechecks a five-minute overlap and filters events that were already indexed, preventing events from being missed when timestamps are identical, contain fractional seconds, or arrive late.
- Policy and Account Admin Audit collection no longer retries indefinitely after API rate limits or temporary connection failures. Requests honor
Retry-Afterand stop after a limited number of retries. If Account Admin Audit collection cannot complete, the input preserves the last successful checkpoint so collection can resume during the next run. - Admin Audit API Logout events now use the CIM-prescribed
logoffaction. Account Admin Audit events are no longer mapped to Change.Account_Management based on anAPI Logoutdescription alone, as described in Upgrade notes.
Known issues¶
Version 5.0.1 of the Splunk Add-on for CyberArk EPM has the following reported known issues. If no issues appear in this section, no issues have yet been reported:
Third-party software attributions¶
Version 5.0.1 of the Splunk Add-on for CyberArk EPM incorporates the following third-party software or libraries.
Third-party software attributions for the Splunk Add-on for CyberArk EPM