Skip to content

Commit c3d6e5d

Browse files
authored
CyberArk EPM Source doc update (#4985)
* CyberArk EPM Source doc update * Update cyberark-source.md
1 parent 6f77c18 commit c3d6e5d

File tree

3 files changed

+10
-5
lines changed

3 files changed

+10
-5
lines changed

docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cyberark-source.md

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ import useBaseUrl from '@docusaurus/useBaseUrl';
1818

1919
The CyberArk Endpoint Privilege Manager (EPM) is a security solution that helps organizations reduce the risk of information theft or ransomware attacks by enforcing the principle of least privilege and preventing unauthorized access to critical systems and data. The solution employs a combination of privilege security, application control, and credential theft prevention to reduce the likelihood of malware infections.
2020

21-
The integration with CyberArk EPM's API allows for retrieving administrative, detailed raw, policy audit, and policy audit raw events from every set in the environment. The [API documentation](https://docs.cyberark.com/Product-Doc/OnlineHelp/EPM/Latest/en/Content/LandingPages/LPDeveloper.htm) provides guidance on accessing and utilizing this information. This integration facilitates retrieving various audit events, including administrative actions, policy violations, and application usage, to generate alerts, reports, and remediation actions that enhance the organization's security posture.
21+
The integration with CyberArk EPM's API allows for retrieving administrative, detailed raw, policy audit, policy audit raw events, and aggregated events from every set in the environment. The [API documentation](https://docs.cyberark.com/Product-Doc/OnlineHelp/EPM/Latest/en/Content/LandingPages/LPDeveloper.htm) provides guidance on accessing and utilizing this information. This integration facilitates retrieving various audit events, including administrative actions, policy violations, and application usage, to generate alerts, reports, and remediation actions that enhance the organization's security posture.
2222

2323
## Data collected
2424

@@ -29,6 +29,7 @@ The integration with CyberArk EPM's API allows for retrieving administrative, de
2929
| 10 minutes | Detailed Raw Events |
3030
| 10 minutes | Aggregated Policy Audit Events |
3131
| 10 minutes | Policy Audit Raw Events |
32+
| 10 minutes | Aggregated Events |
3233

3334
## Setup
3435

@@ -60,9 +61,10 @@ To configure a CyberArk EPM Source, follow the steps below:
6061
* For the US datacenter, the dispatch server URL is `https://login.epm.cyberark.com`.
6162
* For the EU datacenter, the dispatch server URL is `https://eu.epm.cyberark.com`.
6263
1. **Application ID**. An application ID is a unique identifier that helps an API recognize which application or program is accessing it. It's like a name tag that allows the API to keep track of different applications using it. For example, *sumologic*.
63-
1. **Collect Detailed Raw Events**. This option enables the CyberArk C2C Source to collect detailed raw events from the CyberArk EPM. By default, the source can make 1000 requests every 5 minutes to [Detailed Raw Events](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/GetDetailedRawEvents.htm) endpoint, as stated in the [CyberArk API documentation](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/WebServicesIntro.htm). Use below options to adjust this settings.
64-
1. **Collect Aggregated Policy Audit Events**. This option enables the C2C Source to collect aggregated policy audit events from the CyberArk EPM. By default, the source can make 1000 requests every 5 minutes to [Aggregated Policy Audit Events](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/GetAggregatedPolicyAudits.htm) endpoint, as stated in the [CyberArk API documentation](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/WebServicesIntro.htm). Use below options to adjust this settings.
65-
1. **Collect Policy Audit Raw Events**. This option enables the C2C Source to collect policy audit raw events from the CyberArk EPM. By default, the source can make 1000 requests every 5 minutes to [Policy Audit Raw Events](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/GetPolicyAuditRawEventDetails.htm) endpoint, as stated in the [CyberArk API documentation](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/WebServicesIntro.htm). Use below options to adjust this settings.
64+
1. **Collect Detailed Raw Events**. Select this checkbox to enable the CyberArk C2C Source to collect detailed raw events from the CyberArk EPM. By default, the source can make 1000 requests every 5 minutes to [Detailed Raw Events](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/GetDetailedRawEvents.htm) endpoint, as stated in the [CyberArk API documentation](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/WebServicesIntro.htm).
65+
1. **Collect Aggregated Policy Audit Events**. Select this checkbox to enable the C2C Source to collect aggregated policy audit events from the CyberArk EPM. By default, the source can make 1000 requests every 5 minutes to [Aggregated Policy Audit Events](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/GetAggregatedPolicyAudits.htm) endpoint, as stated in the [CyberArk API documentation](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/WebServicesIntro.htm).
66+
1. **Collect Policy Audit Raw Events**. Select this checkbox to enable the C2C Source to collect policy audit raw events from the CyberArk EPM. By default, the source can make 1000 requests every 5 minutes to [Policy Audit Raw Events](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/GetPolicyAuditRawEventDetails.htm) endpoint, as stated in the [CyberArk API documentation](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/WebServicesIntro.htm).
67+
1. **Collect Aggregated Events**. Select this checkbox to enable the C2C Source to collect aggregated events from the CyberArk EPM. By default, the source can make 1000 requests every 5 minutes to [Aggregated Events](https://docs.cyberark.com/epm/latest/en/content/webservices/getaggregatedevents.htm) endpoint, as stated in the [CyberArk API documentation](https://docs.cyberark.com/EPM/Latest/en/Content/WebServices/WebServicesIntro.htm).
6668
1. **Polling Interval**. The polling interval is the frequency at which the CyberArk C2C Source will check for updates from the CyberArk EPM (Endpoint Privilege Manager). This field is pre-filled with 600.
6769
1. When you are finished configuring the Source, click **Save**.
6870

@@ -100,6 +102,7 @@ Sources can be configured using UTF-8 encoded JSON files with the Collector Ma
100102
| detailed_raw_events | boolean | No | False | Collects detailed raw events. | |
101103
| aggregated_policy_audits | boolean | No | False | Collects aggregated policy audits events. | |
102104
| policy_audit_raw_events | boolean | No | False | Collects policy audit raw events. | |
105+
| aggregated_events | boolean | No | False | Collects policy aggregated events. | |
103106
| polling_interval | integer | Yes | 600 | Frequency of C2C updates from EPM. | |
104107

105108
### JSON example
@@ -128,4 +131,4 @@ When setting the poll frequency, it's recommended to consider these limitations
128131

129132
:::info
130133
Click [here](/docs/c2c/info) for more information about Cloud-to-Cloud sources.
131-
:::
134+
:::

static/files/c2c/cyberark/example.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@
1010
"detailed_raw_events": false,
1111
"aggregated_policy_audits": false,
1212
"policy_audit_raw_events": false,
13+
"aggregated_events": false,
1314
"polling_interval": 600
1415
},
1516
"schemaRef": {

static/files/c2c/cyberark/example.tf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ resource "sumologic_cloud_to_cloud_source" "cyberark_test_source" {
1212
"detailed_raw_events": false,
1313
"aggregated_policy_audits": false,
1414
"policy_audit_raw_events": false,
15+
"aggregated_events": false,
1516
"polling_interval": 600
1617
})
1718
}

0 commit comments

Comments
 (0)