Table of Contents
Overview ↵
About the Splunk Add-on for CyberArk EPM¶
| Component | Description |
|---|---|
| Version | 5.0.1 |
| Splunk platform versions | 9.2, 9.3, 9.4, 10.0, 10.1, 10.2, 10.3, 10.4, 10.5, 10.6 |
| CIM | 8.6.0 |
| Platforms | Platform independent |
| Vendor Products | CyberArk Endpoint Privilege Manager v24.12.1, v25.6.1, v26.4, v26.5.0, v26.5.1, v26.6.0, v26.7.0, v26.7.1, v26.8.2 |
The Splunk Add-on for CyberArk EPM allows a Splunk software administrator to pull raw and aggregated events of Inbox Events, Policy Audit Events, Admin Audit Logs and can also collect logs related to policies, computers, and computer groups using the cloud administration APIs of CyberArk EPM. Inbox Events are comprised of events related to Application Events and Threat Detection events.
Release notes¶
For a summary of new features, fixed issues, and known issues, and for more information on release history, see Release notes for the Splunk Add-on for CyberArk EPM.
Compatibility¶
This add-on provides modular inputs and CIM-compatible knowledge to use with other Splunk apps, such as Splunk Enterprise Security and the Splunk App for PCI Compliance.
This add-on supports Python versions 3.9 through 3.13 and is not compatible with Python 2.
Source types and lookups¶
For more information about the source types for Splunk Add-on for CyberArk EPM, see Source types.
Download the add-on¶
Download the Splunk Add-on for CyberArk EPM from Splunkbase.
Install and configure the add-on¶
To install and configure the Splunk Add-on for CyberArk EPM, see Installation and configuration overview for the Splunk Add-on for CyberArk EPM.
Hardware and software requirements¶
For more information, see Hardware and software requirements.
Alerts¶
The add-on ships with built-in saved searches for detecting operational issues. For a list of available alerts and instructions on how to enable them, see Alerts.
Additional resources¶
See Troubleshooting guidelines specific for this add-on.
Hardware and software requirements¶
You must have access to the CyberArk EPM Admin Console so that you can configure it and send data to the Splunk platform instance. Since this is modular input TA and Universal Forwarders do not come with a UI, Universal Forwarders are not supported for configuration in Splunk Web.
CyberArk EPM requirements¶
-
Supported CyberArk Endpoint Privilege Manager versions are v24.12.1, v25.6.1, v26.4, v26.5.0, v26.5.1, v26.6.0, v26.7.0, v26.7.1, and v26.8.2.
EPM versions prior to v24.12.1 (including v21.10, v23.3.0, and v24.5.0) are not supported because the API endpoints required by this add-on were removed from the EPM product in v24.12.x.
Splunk platform requirements¶
Because this add-on runs on the Splunk platform, all of the system requirements apply to the Splunk software that you use to run this add-on.
- You must be running a supported Splunk Platform version: 9.2, 9.3, 9.4, 10.0, 10.1, 10.2, 10.3, 10.4, 10.5, or 10.6.
- Python 3.9 through 3.13 is required. This add-on is Python 3 only and is not compatible with Python 2.
- For Splunk Enterprise system requirements: see System Requirements in the Splunk Enterprise Installation Manual.
- If you manage on-premises forwarders to get data into Splunk Cloud, see System Requirements in the Splunk Enterprise Installation Manual, which includes information about forwarders.
Release notes for the Splunk Add-on for CyberArk EPM¶
Version 5.0.1 of the Splunk Add-on for CyberArk EPM was released on
About this release¶
Version 5.0.1 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.
| Component | Description |
|---|---|
| Splunk platform versions | 9.2, 9.3, 9.4, 10.0, 10.1, 10.2, 10.3, 10.4, 10.5, 10.6 |
| CIM | 8.6.0 |
| Platforms | Platform independent |
| Vendor Products | CyberArk Endpoint Privilege Manager v24.12.1, v25.6.1, v26.4, v26.5.0, v26.5.1, v26.6.0, v26.7.0, v26.7.1, v26.8.2 |
Upgrade notes¶
- API Logout events for the
cyberark:epm:admin:auditsourcetype now use the CIM-prescribedaction="logoff"value instead ofaction="logout". Update saved searches, dashboards, and alerts that filter on the old value. - The
cyberark_epm_account_admin_audit_logs_account_changesevent type no longer mapscyberark:epm:account:admin:auditevents to Change.Account_Management solely becauseDescriptionbegins withAPI Logout. Events withFeature="Account Mgmt"remain mapped. To find all Account Admin Audit API Logout events directly, usesourcetype="cyberark:epm:account:admin:audit" Description="API Logout*". - These event type changes affect the accelerated Change data model. Splunk software automatically rebuilds an accelerated data model when a referenced event type changes and Automatic Rebuilds is enabled. If Automatic Rebuilds is disabled for the Change data model, rebuild it manually from the Data Model Manager. Searches that use the acceleration summary can return stale results until the rebuild finishes.
Fixed issues¶
Version 5.0.1 of the Splunk Add-on for CyberArk EPM has the following fixed issues. If no issues appear in this section, no issues have yet been reported:
- The add-on no longer forces EPM REST API version
25.6.1in supported API URLs. The EPM server selects its latest available API version, while the Computer Groups endpoint continues to use its documentedv2path. Account validation also provides more actionable messages for HTTP 401, 403, and 404 responses without exposing credentials or tokens. - Account Admin Audit collection now rechecks a five-minute overlap and filters events that were already indexed, preventing events from being missed when timestamps are identical, contain fractional seconds, or arrive late.
- Policy and Account Admin Audit collection no longer retries indefinitely after API rate limits or temporary connection failures. Requests honor
Retry-Afterand stop after a limited number of retries. If Account Admin Audit collection cannot complete, the input preserves the last successful checkpoint so collection can resume during the next run. - Admin Audit API Logout events now use the CIM-prescribed
logoffaction. Account Admin Audit events are no longer mapped to Change.Account_Management based on anAPI Logoutdescription alone, as described in Upgrade notes.
Known issues¶
Version 5.0.1 of the Splunk Add-on for CyberArk EPM has the following reported known issues. If no issues appear in this section, no issues have yet been reported:
Third-party software attributions¶
Version 5.0.1 of the Splunk Add-on for CyberArk EPM incorporates the following third-party software or libraries.
Third-party software attributions for the Splunk Add-on for CyberArk EPM
Release notes history¶
The latest release of Splunk Add-on for CyberArk EPM is version 5.0.1. For information, see Release notes for the Splunk Add-on for CyberArk EPM.
Version 5.0.0¶
Splunk Add-on for CyberArk EPM version 5.0.0 was released on
Compatibility¶
Version 5.0.0 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.
| Component | Description |
|---|---|
| Splunk platform versions | 9.x, 10.0.x |
| CIM | 6.1.0 |
| Platforms | Platform independent |
| Vendor Products | CyberArk Endpoint Privilege Manager v24.12.1, v25.6.1, v26.4 |
Breaking changes¶
-
Removed deprecated inputs: Application Events, Policy Audit, and Threat Detection.
The underlying CyberArk EPM API endpoints (
GET /EPM/API/{version}/Sets/{setId}/Events/{category}) were deprecated by CyberArk in EPM v24.11.1 and removed from the product in EPM v24.12.x. As a result, the following inputs no longer function against current EPM versions and were removed from this add-on:Removed input Removed sourcetype Replacement input Replacement sourcetype Application Events cyberark:epm:application:eventsInbox Events (API type: Aggregated Events) cyberark:epm:aggregated:eventsThreat Detection cyberark:epm:threat:detectionInbox Events (API type: Aggregated Events) cyberark:epm:aggregated:eventsPolicy Audit cyberark:epm:policy:auditPolicy Audit Events (API type: Aggregated Events) cyberark:epm:aggregated:policy:auditMigration steps:
- Create a new Inbox Events input with API Type set to Aggregated Events to replace any existing Application Events or Threat Detection inputs.
- Create a new Policy Audit Events input with API Type set to Aggregated Events to replace any existing Policy Audit inputs.
- Delete the old Application Events, Policy Audit, and Threat Detection inputs.
Note
The new inputs provide richer event schemas and support cursor-based pagination. The sourcetypes are different from the removed ones. Update any saved searches, dashboards, or alerts that reference
cyberark:epm:application:events,cyberark:epm:policy:audit, orcyberark:epm:threat:detection. -
cyberark:epm:computerssourcetype:statusfield values changed.The Policies and Computers input uses the new EPM Endpoints API. The CIM
statusfield is sourced fromconnectionStatusinstead ofStatus, and its values changed:Old value ( Status)New value ( connectionStatus)AliveConnectedDisconnectedDisconnected(not present) NeverConnectedMigration: Update any saved searches, dashboards, or alerts that filter on
status="Alive"to usestatus="Connected"instead. TheNeverConnectedvalue has no equivalent in previous versions. -
Minimum supported CyberArk EPM version is v24.12.1.
EPM versions prior to v24.12.1 (v21.10, v23.3.0, and v24.5.0) are not supported because the API endpoints used by this add-on require EPM v24.12.1 or later.
-
Python 3.7 and 3.8 are no longer supported. Minimum required Python version is 3.9.
Splunk Enterprise 9.0 and later ships with Python 3.9 or later, so most deployments are unaffected.
New features¶
- Added Python 3.13 support. The supported Python range is 3.9-3.13.
- Added the
x-cybr-telemetryHTTP header to all CyberArk EPM API requests. The header identifies the integration to CyberArk and includes the add-on name, version, Splunk platform version, and operating system. No configuration is required. - Account configuration fields now display as required in the UI. All credential fields are marked as mandatory with the standard required field indicator.
Fixed issues¶
Version 5.0.0 of the Splunk Add-on for CyberArk EPM has the following fixed issues. If no issues appear in this section, no issues have yet been reported:
Known issues¶
Version 5.0.0 of the Splunk Add-on for CyberArk EPM has the following reported known issues. If no issues appear in this section, no issues have yet been reported:
Version 4.0.0¶
Splunk Add-on for CyberArk EPM version 4.0.0 was released on
Compatibility¶
Version 4.0.0 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.
| Component | Description |
|---|---|
| Splunk platform versions | 9.x, 10.0.x |
| CIM | 6.1.0 |
| Platforms | Platform independent |
| Vendor Products | CyberArk Endpoint Privilege Manager v21.10, v23.3.0, v24.5.0, v24.12.1, v25.6.1, v26.4 |
New features¶
-
Added support for OAuth2 authentication using the
client_credentialsgrant flow. You can now configure accounts using the OAuth2 (Client Credentials) authentication type, which obtains a JWT access token from CyberArk Identity and caches it for the duration of its validity (up to 12 hours).The following new fields are available when OAuth2 (Client Credentials) authentication is selected:
Field Description Client ID The OAuth2 client ID registered in CyberArk Identity. Client Secret The OAuth2 client secret for the registered application. Identity Tenant URL The base URL of your CyberArk Identity tenant, for example https://<tenant>.id.cyberark.cloud.OAuth2 App Alias The application alias configured in CyberArk Identity for the OAuth2 application. -
Added support for CyberArk EPM v26.4.
Fixed issues¶
Version 4.0.0 of the Splunk Add-on for CyberArk EPM has the following fixed issues. If no issues appear in this section, no issues have yet been reported:
Known issues¶
Version 4.0.0 of the Splunk Add-on for CyberArk EPM has the following reported known issues. If no issues appear in this section, no issues have yet been reported:
Version 3.1.0¶
Splunk Add-on for CyberArk EPM version 3.1.0 was released on July 24, 2025.
Compatibility¶
Version 3.1.0 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.
| Component | Description |
|---|---|
| Splunk platform versions | 9.x, 10.0.x |
| CIM | 6.1.0 |
| Platforms | Platform independent |
| Vendor Products | CyberArk EPM v21.10, v23.3.0, v24.5.0, v25.6.1 |
New features¶
-
Added support for SetID Filter in the input configuration. A new SetID filter option was added to the following inputs:
- Admin Audit Logs
- Inbox Events
- Policy Audit Events
-
Policies and Computers
This enhancement introduces a dropdown menu in the input configuration, allowing you to filter event data based on specific SetIDs and collect events specific to the selected SetID.
Note
The
SetIDvalue will now appear in the raw events for the inputs listed in this section. -
The Common Information Model (CIM) was upgraded from version 5.3.2 to 6.1.0 to maintain compatibility with the latest data models and Splunk best practices.
- Added support of CyberArk EPM API v25.6.1.
Fixed issues¶
Version 3.1.0 of the Splunk Add-on for CyberArk EPM has the following fixed issues. If no issues appear in this section, no issues have yet been reported:
Known issues¶
Version 3.1.0 of the Splunk Add-on for CyberArk EPM has the following reported known issues. If no issues appear in this section, no issues have yet been reported:
Version 3.0.0¶
Splunk Add-on for CyberArk EPM version 3.0.0 was released on January 30, 2025.
Compatibility¶
Version 3.0.0 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.
| Component | Description |
|---|---|
| Splunk platform versions | 9.0.x 9.1.x, 9.2.x, 9.3.x, 9.4.x |
| CIM | 5.3.2 |
| Platforms | Platform independent |
| Vendor Products | CyberArk EPM v21.10, v23.3.0, v24.5.0 |
New features¶
- Introduced new input to collect Account Admin Audit Logs for improved tracking of account admin activities.
- Added CIM support of the Change data model to the Account Admin Audit Logs collected using the modular input.
- Added support for the UCC Monitoring Dashboard.
- This dashboard enables users to visualize data volume metrics based on source, index, sourcetype, event trendlines etc, and also visualize errors in the Splunk add-on for CyberArk EPM.
- Added validation for the URLs that do not use basic authentication when you provide a EPM Dispatcher Server URL value during account configuration.
Fixed issues¶
Version 3.0.0 of the Splunk Add-on for CyberArk EPM has no reported fixed issues.
Known issues¶
Version 3.0.0 of the Splunk Add-on for CyberArk EPM has no reported known issues.
Version 2.1.0¶
Splunk Add-on for CyberArk EPM version 2.1.0 was released on July 22, 2024.
Compatibility¶
Version 2.1.0 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.
| Component | Description |
|---|---|
| Splunk platform versions | 9.0.x 9.1.x, 9.2.x |
| CIM | 5.3.2 |
| Platforms | Platform independent |
| Vendor Products | CyberArk EPM v21.10, v23.3.0, v24.5.0 |
New features¶
- Support for CyberArk EPM APIs v24.5.0.
- Introduced new input for fetching Admin Audit Logs.
- Added CIM support of the Change data model to the Admin Audit Logs collected using the modular input.
- IPv6 support - the Splunk Add-on for CyberArk EPM is now compatible with Splunk running on the IPv6 environment.
- Support of Python 3.9.
Fixed issues¶
Version 2.1.0 of the Splunk Add-on for CyberArk EPM has no reported fixed issues.
Known issues¶
Version 2.1.0 of the Splunk Add-on for CyberArk EPM has no reported known issues.
Version 2.0.1¶
Splunk Add-on for CyberArk EPM version 2.0.1 was released on December 12, 2023.
Compatibility¶
Version 2.0.1 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.
| Component | Description |
|---|---|
| Splunk platform versions | 9.0.x 9.1.x |
| CIM | 5.1.0 |
| Platforms | Platform independent |
| Vendor Products | CyberArk EPM v21.10, v23.3.0 |
New features¶
Fixed the security vulnerabilities found in the certifi and urllib3 libraries by upgrading their versions from 2022.12.7 to 2023.11.17 and 1.26.9 to 1.26.18 respectively.
Fixed issues¶
Version 2.0.1 of the Splunk Add-on for CyberArk EPM has no reported fixed issues.
Known issues¶
Version 2.0.1 of the Splunk Add-on for CyberArk EPM has no reported known issues.
Version 2.0.0¶
Splunk Add-on for CyberArk EPM version 2.0.0 was released on March 27, 2023.
Compatibility¶
Version 2.0.0 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.
| Component | Description |
|---|---|
| Splunk platform versions | 8.1, 8.2, 9.0.x |
| CIM | 5.1.0 |
| Platforms | Platform independent |
| Vendor Products | CyberArk EPM v21.10, v23.3.0 |
New features¶
Version 2.0.0 of the Splunk Add-on for CyberArk EPM provides the following improvement:
- Support for CyberArk EPM APIs v23.3.0
- Support for Raw Events along with Aggregated Events
- Introduced 2 new inputs which collects data using both the API types - Inbox Events and Policy Audit Events
- Introduced 4 new sourcetypes. 2 each for both the inputs -
cyberark:epm:raw:events- Collects Inbox Events from raw API endpointcyberark:epm:aggregated:events- Collects Inbox Events from aggregated API endpointcyberark:epm:raw:policy:audit- Collects Policy Audit Events from raw API endpointcyberark:epm:aggregated:policy:audit- Collects Policy Audit Events from aggregated API endpoint
- Added functionality of “Start Date” to start the data collection as and when needed, for the 2 new inputs
- Provided support of CIM version 5.1.0
- Upgraded certifi library to version 2022.12.7 to fix a security vulnerability
Application Events, Policy Audit, and Threat Detection are marked as deprecated inputs in the UI. When configuring these inputs, a warning message appears that suggests using the newly introduced input to utilize the enhanced APIs introduced by CyberArk. The deprecated inputs will be removed in a future release.
Fixed issues¶
Version 2.0.0 of the Splunk Add-on for CyberArk EPM has no reported fixed issues.
Known issues¶
Version 2.0.0 of the Splunk Add-on for CyberArk EPM has no reported known issues.
Version 1.2.0¶
Splunk Add-on for CyberArk EPM version 1.2.0 was released on December 2, 2021.
Compatibility¶
Version 1.2.0 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.
| Component | Description |
|---|---|
| Splunk platform versions | 8.0, 8.1, 8.2 |
| CIM | 4.20.2 |
| Platforms | Platform independent |
| Vendor Products | CyberArk EPM v11.6, v21.10 |
Note
The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.
For more information about the field alias configuration change, see the Splunk Enterprise Release Notes.
New features¶
Version 1.2.0 of the Splunk Add-on for CyberArk EPM provides the following improvement:
- Support for CyberArk EPM v21.10 Enhanced CIM mapping and compatibility with CIM v4.20.2
- For
cyberark:epm:computerssourcetype added Inventory Data Model mappings. - For
cyberark:epm:threat:detectionsourcetype ThreatDetectionAction=Detected Data Model has been changed from Change DM to Intrusion Detection DM. - Due to DM changes the following changes have been made for these events:
destfield has been removed from these events.actionfield value has been changed from read to allowed.
Known issues¶
Version 1.2.0 of the Splunk Add-on for CyberArk EPM has no reported known issues.
Version 1.1.0¶
Splunk Add-on for CyberArk EPM version 1.1.0 was released on July 14, 2021.
Compatibility¶
Version 1.1.0 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.
| Component | Description |
|---|---|
| Splunk platform versions | 8.0, 8.1, 8.2 |
| CIM | 4.16 |
| Platforms | Platform independent |
| Vendor Products | CyberArk EPM v11.6 |
Note
The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.
For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.
New features¶
Version 1.1.0 of the Splunk Add-on for CyberArk EPM provides the following improvement:
- Support for the latest UCC Framework 5.4.3.
- Restarts on search heads are no longer required.
Known issues¶
Version 1.1.0 of the Splunk Add-on for CyberArk EPM has no reported known issues.
Version 1.0.0¶
Compatibility¶
Version 1.0.0 of the Splunk Add-on for CyberArk EPM is compatible with the following software, CIM versions, and platforms.
| Component | Description |
|---|---|
| Splunk platform versions | 8.0 |
| CIM | 4.16 |
| Platforms | Platform independent |
| Vendor Products | CyberArk EPM v11.6 |
Note
The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.
For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.
New features¶
Version 1.0.0 of the Splunk Add-on for CyberArk EPM provides the following features:
- Let a Splunk software administrator pull aggregated events of Application Events, Policy Audit, and Threat Detection categories using the cloud administration APIs of CyberArk EPM.
- Collects logs related to Policies, Computers, and Computer Groups.
- Supported the following Data Models (CIM v4.16):
- Change
- Intrusion Detection
- Endpoint
Known issues¶
Version 1.0.0 of the Splunk Add-on for CyberArk EPM has no reported known issues.
Third-party software attribution¶
A complete listing of third-party software information for version 5.0.1 of this add-on is available as a PDF file for download: Third-party credits for version 5.0.1.
Installation overview¶
Complete the following steps to install and configure this add-on.
Ended: Overview
Installation ↵
Install the Splunk Add-on for CyberArk EPM¶
Use the tables to determine where and how to install this add-on in your deployment.
If you need step-by-step instructions on how to install an add-on in your specific deployment environment, see the installation walkthroughs section at the bottom of this page for links to installation instructions specific to a single-instance deployment, distributed deployment, or Splunk Cloud.
Distributed deployments¶
Use the tables on this page to determine where and how to install this add-on in a distributed deployment of Splunk Enterprise or any deployment for which you are using forwarders to get your data in. Depending on your environment, your preferences, and the requirements of the add-on, you may need to install the add-on in multiple places.
Where to install this add-on¶
Unless otherwise noted, all supported add-ons can be safely installed to all tiers of a distributed Splunk platform deployment. See Installing add-ons in Splunk Add-ons for more information.
This table provides a reference for installing this specific add-on to a distributed deployment of Splunk Enterprise.
| Splunk instance type | Required | Supported | Comments |
|---|---|---|---|
| Search Heads | Yes | Yes | Install this add-on to all search heads where CyberArk knowledge management is required. |
| Indexers | No | Yes | Not required, because this add-on does not include any index-time operations. |
| Heavy Forwarders | Yes | Yes | |
| Universal Forwarders | No | No |
Distributed deployment feature compatibility¶
This table describes the compatibility of this add-on with Splunk distributed deployment features.
| Distributed deployment feature | Supported | Actions required |
|---|---|---|
| Search Head Clusters | Yes | You can install this add-on on a search head cluster for all search-time functionality, but configure inputs only on a forwarder to avoid duplicate data collection. |
| Indexer Clusters | Yes | |
| Deployment Server | Yes | Supported for deploying configured add-on to multiple nodes. |
Installation walkthroughs¶
The Splunk Add-Ons manual includes an Installing add-ons guide that helps you successfully install any Splunk-supported add-on to your Splunk platform.
For a walkthrough of the installation procedure, follow the link that matches your deployment scenario:
Ended: Installation
Configuration ↵
Configure the Splunk Add-on for CyberArk EPM¶
Use the user interface to set up CyberArk EPM credentials and optional proxy and logging levels. When you complete this task, you then configure inputs.
Set up your account¶
Use Splunk Web to set up your CyberArk EPM account to collect data and make it available to Splunk.
- In the Splunk Add-on for CyberArk EPM go to the Accounts tab.
- Click Add.
- Add a unique Account Name.
- Add the EPM Server URL. The URL must start with
httpsand must not contain a path, query, or fragment.- For Basic Auth, use the dispatcher URL (e.g.
https://login.epm.cyberark.com). - For OAuth2, use your specific EPM server node URL (e.g.
https://naXXX.epm.cyberark.com).
- For Basic Auth, use the dispatcher URL (e.g.
- Select an Authentication Type:
- Basic (Username/Password) — authenticate using a CyberArk EPM username and password.
- OAuth2 (Client Credentials) — authenticate using an OAuth2 client credentials flow via CyberArk Identity.
- Complete the fields for the selected authentication type (see below).
- Click Add to save the new account.
Basic (Username/Password)¶
| Field | Description |
|---|---|
| Username | The CyberArk EPM account username. |
| Password | The CyberArk EPM account password. |
OAuth2 (Client Credentials)¶
OAuth2 authentication uses the client_credentials grant flow. The add-on obtains a JWT access token from CyberArk Identity and caches it for the duration of its validity (up to 12 hours). The token is automatically refreshed when it expires.
| Field | Description |
|---|---|
| Client ID | The service user login name configured in CyberArk Identity for this OAuth2 application. |
| Client Secret | The service user password configured in CyberArk Identity for this OAuth2 application. |
| Identity Tenant URL | The base URL of your CyberArk Identity tenant — hostname only, no path (e.g. https://axXXX.id.cyberark.cloud). |
| OAuth2 App Alias | The web application alias configured in CyberArk Identity Administration for this OAuth2 app (e.g. MyEPMApp). |
Note
When using OAuth2 authentication, the EPM Server URL must be the URL of your specific EPM server node — not the dispatcher URL. The add-on uses this URL directly for all API calls. Use the hostname-only format with no path (e.g. https://naXXX.epm.cyberark.com).
The add-on does not force an EPM REST API version in supported API URLs. The EPM server automatically uses its latest available API version, as recommended by CyberArk.
Set up Proxy and Logging level¶
If you are using a proxy, you must set up your proxy and logging levels.
- Check Enable Proxy.
- Specify the Host, Port, Username, and Password values.
- Check DNS resolution to perform DNS resolution through your proxy.
- Select your proxy type in the Proxy Type field.
- Optionally select a different Logging level.
- Click Save.
Configure inputs¶
Breaking change in v5.0.0
The Application Events, Policy Audit, and Threat Detection inputs were removed in v5.0.0. The underlying CyberArk EPM API endpoints were removed by CyberArk in EPM v24.12.x. If you are upgrading from an earlier version, migrate your existing inputs before upgrading:
| Removed input | Replacement input | Replacement API type |
|---|---|---|
| Application Events | Inbox Events | Aggregated Events |
| Threat Detection | Inbox Events | Aggregated Events |
| Policy Audit | Policy Audit Events | Aggregated Events |
Update any saved searches, dashboards, or alerts that reference the sourcetypes cyberark:epm:application:events, cyberark:epm:policy:audit, or cyberark:epm:threat:detection.
The following input type is new as of version 3.0.0. This input has a “Start Date” field which can be configured by the user to collect data from the desired date and time:
- Account Admin Audit Logs
The following input type is new as of version 2.1.0. This input has a “Start Date” field which can be configured by the user to collect data from the desired date and time:
- Admin Audit Logs
The following input types are new as of version 2.0.0. These inputs have a “Start Date” field which can be configured by the user to collect data from the desired date and time:
- Inbox Events
- Policy Audit Events
The Splunk Add-on for CyberArk EPM collects all events for the Policies and Computers input type.
For supported EPM REST endpoints, the add-on omits the API version so that the EPM server selects its latest available version. The dedicated Computer Groups endpoint continues to use its documented v2 path.
Configure inputs¶
You can use Splunk Web to configure these inputs.
- Go to the Inputs tab.
- Select Create New Input.
- Select an Input Type.
- Enter the details using the following input parameters tables and select the Add button.
Account Admin Audit logs¶
| Field | Description |
|---|---|
| Account (required) | The CyberArk EPM account to use to get the data in. The account should already be configured on the Configuration page. |
| Interval (required) | Data collection interval. (Default value: 300) |
| Index (required) | Index to ingest data in. |
| Start Date (optional) | Date to start the data collection from. Default value is current UTC time - 6 minutes |
Admin Audit logs¶
| Field | Description |
|---|---|
| Account (required) | The CyberArk EPM account to use to get the data in. The account should already be configured on the Configuration page. |
| Interval (required) | Data collection interval. (Default value: 300) |
| Index (required) | Index to ingest data in. |
| Start Date (optional) | Date to start the data collection from. Default value is current UTC time - 6 minutes |
| SetIDs (required) | Fetch data only for the selected Set IDs to ensure targeted and relevant event collection. Note: The SetID value will now appear in the raw events. |
Inbox events¶
| Field | Description |
|---|---|
| Account (required) | The CyberArk EPM account to use to get the data in. The account should already be configured on the Configuration page. |
| Application Type (required) | Type of application that triggers the event. Utilises “IN” filter operation in API (Default value: All, Valid application types as per the API document of CyberArk EPM: Executable, Script, MSI, MSU, ActiveX, Com, Win8App, DLL, AdminTask, URL, UserRequest, Temp, DMG, PKG, MacAdminTask, MacExecutable) |
| Publisher(optional) | A digital signature of the application that triggered the event (if applicable). Utilises “CONTAINS” filter operation in API |
| Interval (required) | Data collection interval. (Default value: 360) |
| Index (required) | Index to ingest data in. |
| Justification (optional) | Determines if the event has justification details (Valid values: NULL, NOTNULL). Utilises “IS” filter operation in API |
| Start Date (optional) | Date to start the data collection from. Default value: current UTC time - 6 minutes |
| Api Type (required) | Type of API the user wants to collect data from (Valid values: Raw Events, Aggregated Events). Raw Events API Type brings enriched data and detailed events from the EPM environment. |
| SetIDs (required) | Fetch data only for the selected Set IDs to ensure targeted and relevant event collection. Note: The SetID value will now appear in the raw events. |
Policy Audit events¶
| Field | Description |
|---|---|
| Account (required) | The CyberArk EPM account to use to get the data in. The account should already be configured on the Configuration page. |
| Application Type (required) | Type of application that triggers the event. Utilizes “IN” filter operation in API (Default value: All, Valid application types as per the API document of CyberArk EPM: Executable, Script, MSI, MSU, ActiveX, Com, Win8App, DLL, AdminTask, URL, UserRequest, Temp, DMG, PKG, MacAdminTask, MacExecutable) |
| Publisher(optional) | A digital signature of the application that triggered the event (if applicable). Uses the “CONTAINS” filter operation in the API. |
| Policy Name(optional) | Name of the policy that triggers the event. Utilizes “CONTAINS” filter operation in API |
| Interval (required) | Data collection interval. (Default value: 360) |
| Index (required) | Index to ingest data in. |
| Justification (optional) | Determines if the event has justification details (Valid values: NULL, NOTNULL). Utilises “IS” filter operation in API |
| Start Date (optional) | Date to start the data collection from. Default value: current UTC time - 6 minutes |
| Api Type (required) | Type of API the user wants to collect data from (Valid values: Raw Events, Aggregated Events). Raw Events API Type brings enriched data and detailed events from the EPM environment. |
| SetIDs (required) | Fetch data only for the selected Set IDs to ensure targeted and relevant event collection. Note: The SetID value will now appear in the raw events. |
Policies and Computers¶
Note that the Interval field cannot be modified and is fixed to 86400 seconds. It will fetch all available events on each invocation.
| Field | Description |
|---|---|
| Account (required) | The CyberArk EPM account to get the data in. The account should be configured on the Configuration page. |
| Collect Data For (required) | Collects data for selected options. Default value: Policies, Computers, or Computer Groups |
| Collect Policy Details | A checkbox to collect the Policy details. |
| Index (required) | Index to ingest data in. |
| SetIDs (required) | Fetch data only for the selected Set IDs to ensure targeted and relevant event collection. Note: The SetID value will now appear in the raw events. |
Ended: Configuration
Troubleshooting ↵
Troubleshoot the Splunk Add-on for CyberArk EPM¶
For troubleshooting tips that apply to all add-ons, see Troubleshoot add-ons in Splunk Add-ons. For additional resources, see Support and resource links for add-ons in Splunk Add-ons.
Delay in data ingestion¶
Before performing the task below, verify that you provided the correct CyberArk EPM account information and that your inputs are configured correctly.
Verify your API call limits:
- Go to Configuration > Logging and set the log level to DEBUG.
-
Execute:
index="_internal" source="*splunk_ta_cyberark_epm*" "EPM API rate limit reached" -
Check for the following log message:
EPM API rate limit reached: <details>. Retrying after 10 seconds.This message indicates that the input is working but it is hitting the API call limit of your account. The add-on retries automatically.
-
To increase the API limit for your account, contact CyberArk Support at support@cyberark.com.
See the CyberArk documentation for more details on API limitations at https://community.cyberark.com/s/article/EPM-RestAPI-Limitations.
The add-on includes built-in saved searches for detecting operational issues such as API rate limits. For details, see Alerts.
Data is not ingested in Splunk¶
For best results when experiencing data ingestion or collection issues, use the latest supported version of the Splunk Add-on for CyberArk EPM.
- Verify Account and Inputs are configured properly.
- Verify KV Store is enabled and working.
- Check that data is available within the time range. By default, the add-on starts collecting the data generated within the last 6 minutes on the EPM server. After that, it collects the data as per the last ingested event.
- To collect historical data, you can utilize the “Start Date” field provided in the new inputs.
Note
See CyberArk EPM API limitation documentation for details regarding number of allowed API calls within a time range.
Event truncation¶
For sourcetype cyberark:epm:policies, when the user selects collect_policy_details option to collect the details of the policy, then it might happen that the event gets truncated because the policy details are more in length but Splunk allows an event of maximum 10k bytes.
Issue with account configuration¶
- If “EPM server cannot process the request. Bad Request” error is encountered in the UI during account configuration, make sure there is no whitespace in the username field.
- If “Could not connect to
<url>. Check configuration and network settings.” error is encountered in the UI during account configuration, make sure that the EPM server can be reached and the URL does not contain any whitespace or path components. - To further troubleshoot any issue, check the logs file.
Alerts for the Splunk Add-on for CyberArk EPM¶
The add-on ships with built-in saved searches that detect operational issues during data collection. All alerts are disabled by default and must be enabled manually.
How to find and enable alerts¶
- In Splunk Web, go to Settings > Searches, reports, and alerts.
- In the App filter, select Splunk Add-on for CyberArk EPM.
- Locate the alert you want to enable and click Edit > Enable.
Built-in alerts¶
CyberArk EPM - API Rate Limit Reached¶
Detects repeated API rate limit or request timeout errors in the add-on’s internal logs.
| Property | Value |
|---|---|
| Schedule | Every 15 minutes |
| Search window | Last 15 minutes |
| Severity | Informational |
| Suppression | 1 hour per input and reason |
Trigger condition: More than 5 rate limit or timeout events for a given input within the search window.
What it reports: Which input is affected, whether the cause is a rate limit or a timeout, and the time range of the first and last occurrence.
What to do: The add-on retries automatically. If the alert fires repeatedly, consider reducing the number of active inputs, increasing the polling interval, or contacting CyberArk Support at support@cyberark.com to raise your API call limit.
Note
This alert covers the Admin Audit Logs, Inbox Events, and Policy Audit Events inputs. The Account Admin Audit Logs input is not included in the alert search scope.
Ended: Troubleshooting
Reference ↵
Events for the Splunk Add-on for CyberArk EPM¶
This section lists some of the most relevant EPM events you can collect.
Account Admin Audit Logs¶
- Account related action carried out by EPM administrator.
Admin Audit Logs¶
- Action carried out by EPM administrator.
Credential theft¶
- Browsers
- IT applications
- Remote Access Applications
- Windows OS
Privilege threats¶
Request to boot in Safe Mode Request to set “Always Install Elevated” Privilege deception Privilege Management events.
High risk applications¶
- CMD
- PowerShell
- admin tasks (for example, mmc, local groups, network settings, and so on.)
- Unsigned applications that require elevation
- Blocked applications due to organization policy
- Creation of a JIT policy
You can identify these events using a combination of output fields (like EventName, EventType, PolicyName, Action, and so on) as described in your CyberArk EPM documentation.
Lookups for the Splunk Add-on for CyberArk EPM¶
The Splunk Add-on for CyberArk EPM has the following lookups. The CSV lookup files are located in $SPLUNK\_HOME/etc/apps/Splunk\_TA\_cyberark\_epm/lookups.
| Lookup name | Description |
|---|---|
| cyberark_epm_action_name.csv | Action(integer) field from the event is mapped to the ActionName field in sourcetype cyberark:epm:policies |
Source types¶
The Splunk Add-on for CyberArk EPM supports the following source types.
| Source type | Event type | CIM compatibility |
|---|---|---|
| cyberark:epm:account:admin:audit | cyberark_epm_account_admin_audit_logs_all_changes, cyberark_epm_account_admin_audit_logs_account_changes | Change - All_Changes, Change - Account_Management |
| cyberark:epm:admin:audit | cyberark_epm_admin_audit_logs_all_changes, cyberark_epm_admin_audit_logs_account_changes | Change - All_Changes, Change - Account_Management |
| cyberark:epm:policies | N/A | N/A |
| cyberark:epm:computers | cyberark_epm_computers | Inventory |
| cyberark:epm:computer:groups | N/A | N/A |
| cyberark:epm:raw:events | cyberark_epm_raw_events_endpoint_process, cyberark_epm_events_ids_attack, cyberark_epm_events_malware_attack | Endpoint - Processes, Intrusion Detection, Malware Attacks |
| cyberark:epm:aggregated:events | cyberark_epm_events_ids_attack, cyberark_epm_events_malware_attack | Intrusion Detection, Malware Attacks |
| cyberark:epm:raw:policy:audit | cyberark_epm_raw_policyaudit_endpoint_process | Endpoint - Processes |
| cyberark:epm:aggregated:policy:audit | N/A | N/A |
API Logout events for the cyberark:epm:admin:audit sourcetype use action="logoff". For the cyberark:epm:account:admin:audit sourcetype, an API Logout description alone does not map an event to Change.Account_Management; events with Feature="Account Mgmt" remain mapped. To find all Account Admin Audit API Logout events directly, use sourcetype="cyberark:epm:account:admin:audit" Description="API Logout*".