https://store-images.s-microsoft.com/image/apps.30524.abc89a8b-0d90-47dc-aee9-09d0116c9f34.b6ff7115-630c-4424-b90b-0f081893311b.e33eb51c-6dd5-4b2b-ade7-0e6809598da2

CyberArk Audit for Microsoft Sentinel

CyberArk

CyberArk Audit for Microsoft Sentinel

CyberArk

Extract events from CyberArk Audit service and inject into Microsoft Sentinel

Note: There may be known issues pertaining to this solution, please refer to them before installing.

CyberArk supports third-party SIEM applications integrated with Audit service, that provides audit trails for activities, events, and sessions that are performed by any integrated service on the Identity Security Platform Shared Services. SOC analysts initiate threat investigations through Microsoft Sentinel, which integrates seamlessly with CyberArk Audit. By leveraging the rich audit trail data from CyberArk Audit, the solution ensures a comprehensive view of system and user activities. Automated workflows within Microsoft Sentinel enable real-time response to identified threats, enhancing the overall efficiency and effectiveness of incident response processes.

Data Connectors: 1

Audit Service to Microsoft Sentinel User Guide

Learn more about Microsoft Sentinel | Learn more about CyberArk Audit Service