CyberArk Audit New CCF Data Connector#13473
Conversation
|
Hi @nitsan-tzur Thanks! |
|
Hi @v-maheshbh, attaching relevant screenshots of connected status and recent data fetch from target custom table |
|
Hi @nitsan-tzur Thanks! |
It was discussed and agreed with Microsoft team we've worked with on CCF to not deprecate the Azure Functions connector at this point |
|
Hi @nitsan-tzur Thanks! |
Hi @v-maheshbh, |
Co-authored-by: nitsan-tzur <153099157+nitsan-tzur@users.noreply.github.com>
|
Hi @nitsan-tzur The solution contains three analytical rules, which are not reflected here.
|
Hi @v-maheshbh updated Analytic Rules in createUiDefinition.json |
|
Hi @nitsan-tzur
Thanks! |
Hi @v-maheshbh please see screen shots of successful deployment with corresponding paramters. |
This reverts commit 0369733.
|
Hi @nitsan-tzur I checked on my end and I'm getting a deployment error. Please verify using the latest main template. Thanks! |
Hi @v-maheshbh |
Update CyberArkAudit solution package (3.1.0) and ARM/UI templates. Changes include UI text simplification and wording updates, renaming/reshuffling of analytic section labels and descriptions, removal of some duplicate guidance, and minor metadata tweaks. mainTemplate.json: swap/rename workspace parameters, add three AnalyticsRule template objects (scheduled rules) with queries and metadata, introduce stepId variable usage, update data connector titles and graph table name to CyberArkAuditV2_CL, add x-cybr-telemetry header, fix OAuth label casing, and include manual Azure Functions deployment instructions. Also update stream/CL schema (column order/types) and transformKql to cast dynamic fields. Binary package 3.1.0.zip was updated to match these changes.
|
Hi @nitsan-tzur Kindly note that I have repackaged the solution, as the analytic rule was not previously updated correctly in the mainTemplate.json. Thanks! |
Hi @v-maheshbh, |
|
Hi @nitsan-tzur
Thanks! |
Hi @v-maheshbh, Table renamed as suggested but template validation is still failing on same error: |
Add explicit GUID ids to three CyberArk analytics rule YAMLs and update mainTemplate.json to reference those IDs (contentId, analyticRuleId, template spec names, and product productIds). Bump API versions for CyberArkAuditDCR and CyberArk_AuditEvents_CL to 2025-07-01. Replace variable stepId usage with literal CreateQuery and normalize fieldMappings key order. Update packaged artifact 3.1.0.zip.
Hi @nitsan-tzur The above error was encountered because the GUID was missing in the analytical rule. This issue has now been resolved. Thanks! |
|
Hi @nitsan-tzur Kindly review and address the above comments. Thanks! |
Hi @v-maheshbh, Getting this error after connecting: |
|
@v-maheshbh I pushed a fix addressing latest deployment error. |
|
Hi @nitsan-tzur Kindly update the datatype of the timestamp field in both the DCR and the corresponding custom table schema. This will ensure the updated schema is reflected correctly in the packaged solution and in the main template. Please avoid manual updates to the main template, as this is not recommended. Thanks! |
Hi @v-maheshbh, |
Update CyberArkAudit package (3.1.0.zip) and mainTemplate.json. Swap/rename the 'workspace' and 'workspace-location' parameter blocks (adjusting defaultValue and metadata; workspace-location description now uses a concat with parameters('location')). Normalize entityMappings across multiple rule definitions by moving 'entityType' before 'fieldMappings' and standardizing the order of 'columnName' and 'identifier' in field mappings for Account/Host/IP entries. These edits tidy the JSON structure and improve consistency.
|
Hi @nitsan-tzur Thanks! |
Hi @v-maheshbh, |















Required items, please complete
Change(s):
Reason for Change(s):
Testing Completed: