Lookups for the Splunk Add-on for CyberArk EPM
The Splunk Add-on for CyberArk EPM has the following lookups. The CSV lookup files are located in $SPLUNK_HOME/etc/apps/Splunk_TA_cyberark_epm/lookups
Lookup name | Description |
---|---|
cyberark_epm_action_name.csv | Action(integer) field from the event is mapped to the ActionName field in sourcetype cyberark:epm:policies |
Events for the Splunk Add-on for Cyberark EPM | Troubleshoot the Splunk Add-on for CyberArk EPM |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!