CyberArk Audit | Sumo Logic Docs

Meet Mobot, our AI assistant that turns plain-language questions into log queries to accelerate investigations and simplify security workflows.

Overview

The Sumo Logic app for CyberArk Audit is a robust tool that provides insights into your organization's cybersecurity practices. It helps IT and security teams monitor, analyze, and visualize audit trails of user activities, security events, and anomalies. By tracking data on security events, identity management, component usage, and administrative actions, the app delivers actionable intelligence to identify and mitigate security risks, ensuring compliance with regulations and internal policies. Customizable dashboards and detailed reporting enhance its ability to strengthen security.

This app includes built-in monitors. For details on creating custom monitors, refer to Create monitors for CyberArk Audit app.

Log types

This app uses Sumo Logic’s CyberArk Audit source to collect the audit logs from the CyberArk Audit platform.

Sample log messages

Audit Log

{
  "uuid": "c131ad7d-af67-4a80-907c-3f982ef5d3be",
  "tenantId": "9880566d-4831-4a33-9e11-f4958deae142",
  "timestamp": 1742370356027,
  "username": "PVWAGWUser",
  "applicationCode": "PAM",
  "auditCode": "PAM00088",
  "auditType": "Info",
  "action": "Set Password",
  "userId": "PVWAGWUser",
  "source": "PVWAAPP",
  "actionType": "Password",
  "component": "Vault",
  "serviceName": "Privilege Cloud",
  "accessMethod": null,
  "accountId": "",
  "target": "",
  "command": null,
  "sessionId": null,
  "message": "",
  "customData": {
    "PAM": {
      "new_target": "",
      "target": ""
    }
  },
  "cloudProvider": null,
  "cloudWorkspacesAndRoles": [],
  "cloudIdentities": null,
  "cloudAssets": null,
  "safe": "",
  "accountName": "",
  "targetPlatform": "",
  "targetAccount": "",
  "identityType": null
}

Sample queries

Password Reset Events

_sourceCategory="Labs/CyberArkAudit"
| json "uuid", "auditType", "serviceName", "actionType", "action", "identityType", "source", "auditCode", "timestamp", "tenantId", "username", "userId", "component", "message", "customData" as id, audit_type, service_name, action_type, action, identity_type, source, audit_code, timestamp, tenant_id, username, user_id, component, message, custom_data nodrop
| where service_name matches "{{service_name}}"
| where action_type matches "{{action_type}}"
| where audit_type matches "{{audit_type}}"
| where component matches "{{component}}"
| where audit_code matches "{{audit_code}}"
| where action matches "{{action}}"
| where if ("{{identity_type}}" = "*", true, identity_type matches "{{identity_type}}")
| where toLowerCase(action_type) matches "password" AND toLowerCase(action) matches "set password"
| count by id
| count

Collection configuration and app installation

Depending on the set up collection method, you can configure and install the app in three ways:

Use the Cloud-to-Cloud Integration for CyberArk Audit to create the source and use the same source category while installing the app. By following these steps, you can ensure that your CyberArk Audit app is properly integrated and configured to collect and analyze your CyberArk Audit data.

Create a new collector and install the app

To set up collection and install the app, do the following:

  1. Select App Catalog.
  2. In the 🔎 Search Apps field, run a search for your desired app, then select it.
  3. Click Install App.
  4. In the Set Up Collection section of your respective app, select Create a new Collector.
  5. Collector Name. Enter a Name to display the Source in the Sumo Logic web application. The description is optional.
  6. Timezone. Set the default time zone when it is not extracted from the log timestamp. Time zone settings on Sources override a Collector time zone setting.
  7. (Optional) Metadata. Click the +Add Metadata link to add a custom log Metadata Fields. Define the fields you want to associate, each metadata field needs a name (key) and value.
  8. Click Next.
  9. Configure the source as specified in the Info box above, ensuring all required fields are included.
  10. Click Next. You will be redirected to the Preview & Done section.