Skip to content

Release notes for the Splunk Add-on for CyberArk EPM

Version 5.0.1 of the Splunk Add-on for CyberArk EPM was released on .

About this release

Version 5.0.1 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.

Component Description
Splunk platform versions 9.2, 9.3, 9.4, 10.0, 10.1, 10.2, 10.3, 10.4, 10.5, 10.6
CIM 8.6.0
Platforms Platform independent
Vendor Products CyberArk Endpoint Privilege Manager v24.12.1, v25.6.1, v26.4, v26.5.0, v26.5.1, v26.6.0, v26.7.0, v26.7.1, v26.8.2

Upgrade notes

  • API Logout events for the cyberark:epm:admin:audit sourcetype now use the CIM-prescribed action="logoff" value instead of action="logout". Update saved searches, dashboards, and alerts that filter on the old value.
  • The cyberark_epm_account_admin_audit_logs_account_changes event type no longer maps cyberark:epm:account:admin:audit events to Change.Account_Management solely because Description begins with API Logout. Events with Feature="Account Mgmt" remain mapped. To find all Account Admin Audit API Logout events directly, use sourcetype="cyberark:epm:account:admin:audit" Description="API Logout*".
  • These event type changes affect the accelerated Change data model. Splunk software automatically rebuilds an accelerated data model when a referenced event type changes and Automatic Rebuilds is enabled. If Automatic Rebuilds is disabled for the Change data model, rebuild it manually from the Data Model Manager. Searches that use the acceleration summary can return stale results until the rebuild finishes.

Fixed issues

Version 5.0.1 of the Splunk Add-on for CyberArk EPM has the following fixed issues. If no issues appear in this section, no issues have yet been reported:

  • The add-on no longer forces EPM REST API version 25.6.1 in supported API URLs. The EPM server selects its latest available API version, while the Computer Groups endpoint continues to use its documented v2 path. Account validation also provides more actionable messages for HTTP 401, 403, and 404 responses without exposing credentials or tokens.
  • Account Admin Audit collection now rechecks a five-minute overlap and filters events that were already indexed, preventing events from being missed when timestamps are identical, contain fractional seconds, or arrive late.
  • Policy and Account Admin Audit collection no longer retries indefinitely after API rate limits or temporary connection failures. Requests honor Retry-After and stop after a limited number of retries. If Account Admin Audit collection cannot complete, the input preserves the last successful checkpoint so collection can resume during the next run.
  • Admin Audit API Logout events now use the CIM-prescribed logoff action. Account Admin Audit events are no longer mapped to Change.Account_Management based on an API Logout description alone, as described in Upgrade notes.

Known issues

Version 5.0.1 of the Splunk Add-on for CyberArk EPM has the following reported known issues. If no issues appear in this section, no issues have yet been reported:

Third-party software attributions

Version 5.0.1 of the Splunk Add-on for CyberArk EPM incorporates the following third-party software or libraries.

Third-party software attributions for the Splunk Add-on for CyberArk EPM