CyberArk Audit | Sumo Logic Docs
Meet Mobot, our AI assistant that turns plain-language questions into log queries to accelerate investigations and simplify security workflows.
Overview
The Sumo Logic app for CyberArk Audit is a robust tool that provides insights into your organization's cybersecurity practices. It helps IT and security teams monitor, analyze, and visualize audit trails of user activities, security events, and anomalies. By tracking data on security events, identity management, component usage, and administrative actions, the app delivers actionable intelligence to identify and mitigate security risks, ensuring compliance with regulations and internal policies. Customizable dashboards and detailed reporting enhance its ability to strengthen security.
This app includes built-in monitors. For details on creating custom monitors, refer to Create monitors for CyberArk Audit app.
Log types
This app uses Sumo Logic’s CyberArk Audit source to collect the audit logs from the CyberArk Audit platform.
Sample log messages
Audit Log
{
"uuid": "c131ad7d-af67-4a80-907c-3f982ef5d3be",
"tenantId": "9880566d-4831-4a33-9e11-f4958deae142",
"timestamp": 1742370356027,
"username": "PVWAGWUser",
"applicationCode": "PAM",
"auditCode": "PAM00088",
"auditType": "Info",
"action": "Set Password",
"userId": "PVWAGWUser",
"source": "PVWAAPP",
"actionType": "Password",
"component": "Vault",
"serviceName": "Privilege Cloud",
"accessMethod": null,
"accountId": "",
"target": "",
"command": null,
"sessionId": null,
"message": "",
"customData": {
"PAM": {
"new_target": "",
"target": ""
}
},
"cloudProvider": null,
"cloudWorkspacesAndRoles": [],
"cloudIdentities": null,
"cloudAssets": null,
"safe": "",
"accountName": "",
"targetPlatform": "",
"targetAccount": "",
"identityType": null
}
Sample queries
Password Reset Events
_sourceCategory="Labs/CyberArkAudit"
| json "uuid", "auditType", "serviceName", "actionType", "action", "identityType", "source", "auditCode", "timestamp", "tenantId", "username", "userId", "component", "message", "customData" as id, audit_type, service_name, action_type, action, identity_type, source, audit_code, timestamp, tenant_id, username, user_id, component, message, custom_data nodrop
| where service_name matches "{{service_name}}"
| where action_type matches "{{action_type}}"
| where audit_type matches "{{audit_type}}"
| where component matches "{{component}}"
| where audit_code matches "{{audit_code}}"
| where action matches "{{action}}"
| where if ("{{identity_type}}" = "*", true, identity_type matches "{{identity_type}}")
| where toLowerCase(action_type) matches "password" AND toLowerCase(action) matches "set password"
| count by id
| count
Collection configuration and app installation
Depending on the set up collection method, you can configure and install the app in three ways:
- Create a new collector and install the app. Create a new Sumo Logic Cloud-to-Cloud (C2C) source under a new Sumo Logic Collector and later install the app, or
- Use an existing collector and install the app. Create a new Sumo Logic Cloud-to-Cloud (C2C) source under an existing Sumo Logic Collector and later install the app, or
- Use existing source and install the app. Use your existing configured Sumo Logic Cloud-to-Cloud (C2C) source and install the app.
Use the Cloud-to-Cloud Integration for CyberArk Audit to create the source and use the same source category while installing the app. By following these steps, you can ensure that your CyberArk Audit app is properly integrated and configured to collect and analyze your CyberArk Audit data.
Create a new collector and install the app
To set up collection and install the app, do the following:
- Select App Catalog.
- In the 🔎 Search Apps field, run a search for your desired app, then select it.
- Click Install App.
- In the Set Up Collection section of your respective app, select Create a new Collector.
- Collector Name. Enter a Name to display the Source in the Sumo Logic web application. The description is optional.
- Timezone. Set the default time zone when it is not extracted from the log timestamp. Time zone settings on Sources override a Collector time zone setting.
- (Optional) Metadata. Click the +Add Metadata link to add a custom log Metadata Fields. Define the fields you want to associate, each metadata field needs a name (key) and value.
- Click Next.
- Configure the source as specified in the
Infobox above, ensuring all required fields are included. - Click Next. You will be redirected to the Preview & Done section.