IMPORTANT: Please use the new App for PM Cloud: https://splunkbase.splunk.com/app/6819/
IMPORTANT: Please use the new App for PM Cloud: https://splunkbase.splunk.com/app/6819/
Minor issue/change: added version="1.1" in dashboard form root node
This Application includes Dashboards that are pre-configured for Privilege Management Cloud
Requirements:
1- Splunk AWS Add-On
2- PMC configured to send SIEM logs to AWS S3 bucket
3- AWS Credentials for Splunk AWS Add-on
4- Events in Splunk from PMC
Each report in the Dashboard filter data like this: sourcetype=aws:s3 "Processes.vendor_product"="Beyondtrust Privilege Management" index=idx_beyondtrust
It is possible to quickly edit each report to replace with desired source, sourcetype, or index.
For any question or feedback, please contact Integrations@beyondtrust.com
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.