---
title: "CyberArk"
slug: "cyberark"
tags: ["Self Service Ingestion"]
updated: 2026-07-02T07:14:30Z
published: 2026-07-02T07:14:30Z
canonical: "docs.hunters.ai/cyberark"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hunters.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# CyberArk

Self Service Ingestion

          

Connect this data source on your own, using the Hunters platform.

****TL;DR****

| Supported data types | 3rd party detection | Hunters detection | IOC search | Search | Table name | Log format | Collection method |
| --- | --- | --- | --- | --- | --- | --- | --- |
| CyberArk Privileged Access Security Logs |  |  | ✅ | ✅ | cyberark_privileged_access_security | CEF | S3 |
| CyberArk Audit Logs |  |  | ✅ | ✅ | cyberark_audit_logs | JSON | S3 |
| CyberArk Identity Logs |  | ✅ | ✅ | ✅ | cyberark_identity_logs | JSON | S3 |

---

## Overview

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/38cd2ca-cyberark.png)CyberArk is a cybersecurity company that specializes in privileged access management (PAM) solutions. Privileged access refers to the elevated permissions and credentials that grant users or applications extensive control over critical systems and sensitive data within an organization. CyberArk's solutions focus on securing and managing these privileged accounts to prevent unauthorized access, misuse, or abuse.

## Send data to Hunters

Hunters supports the ingestion of CyberArk logs via an intermediary AWS S3 bucket.

**To connect CyberArk logs:**

1. Export your logs from CyberArk to an AWS S3 bucket.
2. Once the export is completed and the logs are collected to S3, follow the steps in [this section](/v1/docs/connect-data-through-aws-s3).

## Supported data types

### CyberArk Privileged Access Security Logs

**Table name:** `cyberark_privileged_access_security`

[**CyberArk Privileged Access Security Logs**](https://docs.cyberark.com/pam-self-hosted/11.3/en/content/pasimp/introducing-the-privileged-account-security-solution-intro.htm) provide detailed information about privileged account activity and events within an organization's IT environment. The supported products are:

- Privileged Threat Analytics (PTA)
- On-Demand Privileges Manager (OPM)

## Expected format

(Anonymized) Logs are expected in CEF format.

```plaintext
2023-01-01T00:01:51Z PRODVAULT CEF:0|Cyber-Ark|Vault|6.0.0430|38|Failure: CPM Verify Password Failed|7|
act=CPM Verify Password Failed 
duser=ServiceAccount 
fname=Root\S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX-XXXXX 
src=192.0.2.15 
cs1Label="Affected User Name" cs1= 
cs2Label="Safe Name" cs2=Privileged Accounts Safe 
cs3Label="Location" cs3= 
cs4Label="Property Name" cs4= 
cs5Label="Target User Name" cs5= 
cn1Label="Request Id" cn1= 
msg=Failure. Failure Description: ERROR_CODE Verifying Password Safe: Privileged Accounts Safe, Folder: Root, Object: S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX-XXXXX failed (try #368). 
Code: 2101, 
Error: Error in verifypass to user SERVER01.1.example.local\adminuser on domain SERVER01.1.example.local(\\SERVER01.1.EXAMPLE.LOCAL). 
Reason: No network provider accepted the given network path. (winRc\=1203). , 
address\=SERVER01.1.example.local;
retriescount\=368;
username\=adminuser;, 
Failure: CPM Verify Password Failed
```

### CyberArk Audit Logs

**Table name:** `cyberark_audit_logs`

**CyberArk audit logs** record events generated by the *Conjur Enterprise audit service*, including details about audit log structure and event activity. These logs help administrators monitor security-relevant actions, investigate access or secrets-management activity, and support compliance/audit requirements.

## Expected format

(Anonymized) Logs are expected in JSON format.

```json
{"host":"EXAMPLE.local","source":"10.10.10.10","uuid":"00000000-0000-0000-0000-000000000001","tenantId":"00000000-0000-0000-0000-000000000002","timestamp":1577836800000,"username":"SYSTEM$","applicationCode":"IDP","auditCode":"IDP1001","auditType":"Info","action":"update-user","userId":"NoUser@unknown_user.com","actionType":"Edit","component":"Identity","serviceName":"Identity","message":"update-user","customData":{"authentication_method":"None","when_occurred":"1/1/2020 12:00:00 AM","tenant_id":"EXAMPLE1234","thread_type":"Rpc","mobile_device":"False","level":"Error","directory_service_uuid":"00000000-0000-0000-0000-000000000003","entity_name":"user1@example.com","entity_uuid":"00000000-0000-0000-0000-000000000004","action":"Update","directory_service_type":"AdProxy","directory_service_name":"AdProxy_example.local","status":"NonExist","old_entity":"null","new_entity":"{\"codepage\":\"0\",\"logoncount\":\"0\",\"name\":\" user1\",\"mail\":\"user1@example.com\",\"EntityUuid\":\"00000000-0000-0000-0000-000000000004\",\"distinguishedname\":\"CN= user1,OU=Mailbox Enabled,OU=Accounts User,OU=_Disabled,DC=example,DC=local\",\"whenchanged\":\"1/1/2020 12:00:00 AM\",\"userprincipalname\":\"user1@example.com\",\"samaccountname\":\"1user\",\"displayname\":\" user1\",\"ObjectType\":\"User\",\"EntityName\":\"user1@example.com\"}","classification":"User","password_change":"False","has_cloud_seen_user":"False","has_cloud_seen_entity":"False"},"cloudProvider":"aws","identityType":"HUMAN"}
```

### CyberArk Identity Logs

**Table name:** `cyberark_identity_logs`

**CyberArk Identity Logs** are tenant-level audit records that capture identity and access activities such as authentication, application access, policy enforcement, and administrative actions within the CyberArk Identity platform. They are retrieved through the CyberArk Redrock Query REST API or Syslog Writer and include structured event details with contextual information about related users, devices, applications, groups, and policies.

## Expected format

(Anonymized) Logs are expected in JSON format.

```json
{"host":"ip-10-0-0-1-example-host-1","source":"https://tenant1234.id.cyberark.cloud/Redrock/query","_raw":"{\"Entities\": [{\"Type\": \"Event\", \"Key\": \"00000000-0000-0000-0000-000000000001.W03.094f.examplekey01\", \"IsForeignKey\": false}, {\"Type\": \"Application\", \"Key\": \"cribl_audit_app\", \"IsForeignKey\": true}, {\"Type\": \"User\", \"Key\": \"00000000-0000-0000-0000-000000000002\", \"IsForeignKey\": true}], \"Row\": {\"EventName\": null, \"AdminQuestions\": null, \"AuditState\": null, \"PasswordChangeID\": null, \"TargetAccountName\": null, \"InitiatorID\": null, \"Status\": null, \"ComputerName\": null, \"CountAccounts\": null, \"FailureReason\": null, \"ActionType\": null, \"CountIPhones\": null, \"JobStatus\": null, \"JobScope\": null, \"AgentResourceName\": null, \"JobRetryCount\": null, \"AuthorityFQDN\": null, \"CustomerCompany\": null, \"Description\": null, \"Category\": null, \"ScheduleStartDate\": null, \"AffectedTenant\": null, \"CountDeadProxies\": null, \"CredentialType\": null, \"JobTimeoutSeconds\": null, \"DenyByUser\": null, \"IntelRiskLevel\": null, \"StepArgs\": null, \"AuthoritySource\": null, \"BlessAs\": null, \"DatabaseName\": null, \"TotalUserCount\": null, \"CreatedDate\": null, \"PasswordChangeStatus\": null, \"Principal\": null, \"Key\": null, \"Hostname\": null, \"HttpStatus\": null, \"AdminUsersCount\": null, \"From\": null, \"CanonicalName\": null, \"CountServers\": null, \"FactorOathAuthenticatorLocalized\": null, \"DatabaseID\": null, \"UserName\": null, \"Reason\": null, \"UsePermissionsOnSafe\": null, \"JobMutex\": null, \"CountDeadDevices\": null, \"FactorRadius\": null, \"AgentID\": null, \"FactorMobileAuthenticatorLocalized\": null, \"MemberUuid\": null, \"SessionType\": null, \"IsAppGatewayEnabled\": null, \"TunneledUriPathAndQuery\": null, \"Type\": null, \"CountLiveProxies\": null, \"UpdateAttributes\": null, \"NumGrantAdd\": null, \"NumRightsNeeded\": null, \"ChangerUuid\": null, \"EnrollProfileUser\": null, \"CountAndroidDevices\": null, \"WorkItemCount\": null, \"MultiplexedRealAccount1Name\": null, \"OldState\": null, \"CustomerName\": null, \"AppKey\": null, \"MatchedUsernames\": null, \"Cname\": null, \"OrgId\": null, \"FactorMobileAuthenticator\": null, \"CJoinedServersCount\": null, \"MfaUnlock\": null, \"FactorEmail\": null, \"CloudDnsResolvable\": null, \"TargetPrincipalAction\": null, \"ToDate\": null, \"Row\": null, \"Body\": null, \"TargetFolderName\": null, \"ActualStartedLatencyMs\": null, \"MfaUpgrade\": null, \"ElapsedSeconds\": null, \"Application\": null, \"ReasonInternal\": null, \"EnterpriseId\": null, \"DirectoryName\": null, \"DomainID\": null, \"Module\": null, \"NewAppKey\": null, \"FactorPhoneCall\": null, \"MachineName\": null, \"IsAdminImported\": null, \"OwnerName\": null, \"GatewayPodName\": null, \"NewOwnerName\": null, \"FactorPasswordLocalized\": null, \"LastActivity\": null, \"BlacklistedComputerID\": null, \"StateUpdatedDate\": null, \"Changer\": null, \"DataVaultItemID\": null, \"NewLicenseType\": null, \"PrincipalUuid\": null, \"TunneledUri\": null, \"CountGroups\": null, \"DestUpn\": null, \"CheckedOut\": null, \"DSUuid\": null, \"CountMobileApps\": null, \"JobName\": null, \"MobileAppPrice\": null, \"TotalHourlyCost\": null, \"MobileAppPackageID\": null, \"Thumbprint\": null, \"SecurityQuestionAnswerCount\": null, \"TransferredAppsCount\": null, \"TrusteeType\": null, \"NewState\": null, \"TunneledUriHostname\": null, \"PartialOldLicenseKey\": null, \"TransferredSecuredItemsCount\": null, \"EventSource\": null, \"ForgotPassword\": null, \"WorkflowApproverType\": null, \"WhenDueBack\": null, \"ProfileIdentifier\": null, \"FactorSms\": null, \"OldProfileHash\": null, \"UserState\": null, \"JobExecutionMode\": null, \"CpsServersCount\": null, \"securityQuestion\": null, \"DirectoryServicePartnerName\": null, \"Weekdays\": null, \"TargetPodFqdn\": null, \"CloudHasSeenEntity\": null, \"IsPrivilegedApp\": null, \"SecretType\": null, \"ProxyId\": null, \"DomainName\": null, \"IsPreview\": null, \"ActionPrincipalID\": null, \"CountNotUsingTenantSpecificUrl\": null, \"WorkflowApprover\": null, \"IsForceSync\": null, \"JobId\": null, \"PrincipalsJobId\": null, \"FactorEmailLocalized\": null, \"UpdatedRole\": null, \"RuleName\": null, \"CountChildGroupAndRoles\": null, \"ActiveUsersCount\": null, \"VaultType\": null, \"NumDenyRemove\": null, \"DeviceID\": null, \"ReplaceDomain\": null, \"PrincipalType\": null, \"Roles\": null, \"ConnectorUuid\": null, \"CookieSession\": null, \"ObjectName\": null, \"IssueMode\": null, \"ComputerClass\": null, \"OldValue\": null, \"CountWebApps\": null, \"AccountID\": null, \"Ticket\": null, \"Allowed\": null, \"MfaInitiatorLocalized\": null, \"PasswordResetStatus\": null, \"DeviceName\": null, \"TenantID\": null, \"UpdateTime\": null, \"Value\": null, \"AwsProductCode\": null, \"JobRunAs\": null, \"SyncType\": null, \"Factors\": null, \"NewProfileHash\": null, \"RevokeReason\": null, \"EnterpriseAccountEmail\": null, \"OnPrem\": null, \"CountWindowsDevices\": null, \"UtcDelayedTime\": null, \"ObjectType\": null, \"CredentialId\": null, \"PasswordChangeOverallStatus\": null, \"Subject\": null, \"RuleType\": null, \"FactorForgotPasswordLocalized\": null, \"ChangedFields\": null, \"RoleInstanceId\": null, \"Installation\": null, \"MfaResultLocalized\": null, \"RoleName\": null, \"WindowsAndMacDevicesCount\": null, \"JobStatusDetail\": null, \"CountO365\": null, \"AdminUUID\": null, \"FactorPhoneCallLocalized\": null, \"CountSamsungKnox\": null, \"SyncActionReason\": null, \"ActorUuid\": null, \"OldLicenseType\": null, \"MatchingUserCount\": null, \"UtcActualStartedTime\": null, \"AgentDelete\": null, \"UtcCompletedTime\": null, \"PasswordProfileName\": null, \"CpsServerCostPerHour\": null, \"CountCUSUsers\": null, \"OldEntity\": null, \"CompletedDate\": null, \"SyncActionReasonParam\": null, \"IsRedirectedChallenge\": null, \"SecretFolderName\": null, \"FactorsLocalized\": null, \"CountSafes\": null, \"FactorForgotPassword\": null, \"EnterpriseName\": null, \"PreviousUserState\": null, \"OU\": null, \"IDP\": null, \"AgentDeleteDisplay\": null, \"NumGrantRemove\": null, \"Target\": null, \"CountMacDevices\": null, \"TotalTenantCount\": null, \"Recipients\": null, \"MemberIsGroup\": null, \"PartialLicenseKey\": null, \"CountADUsers\": null, \"AgentFQDN\": null, \"DatabaseServiceName\": null, \"DatabasePort\": null, \"FactorCount\": null, \"CloudHasSeenUser\": null, \"WindowsOrMacDeviceCostPerHour\": null, \"OldOwnerUuid\": null, \"JumpType\": null, \"DSType\": null, \"FolderID\": null, \"CompletedLatencyMs\": null, \"PermissionsLocalized\": null, \"TunneledUriPort\": null, \"SecretName\": null, \"JobGroup\": null, \"CountSamsung\": null, \"Customer\": null, \"UsageTimestamp\": null, \"Table\": null, \"IsTOTPAdded\": null, \"AgentCredential\": null, \"Issuer\": null, \"CountAfwCapable\": null, \"NewUuid\": null, \"LastUsedAt\": null, \"OldOwnerName\": null, \"AppDisplayName\": null, \"ScheduleStartTime\": null, \"AppTypeDisplayName\": null, \"SecretFile\": null, \"CountUsers\": null, \"AppSource\": null, \"FactorU2fLocalized\": null, \"TargetPrincipalID\": null, \"SyncResult\": null, \"ComputerID\": null, \"FactorOathAuthenticator\": null, \"CountIPads\": null, \"CountLogin\": null, \"CredentialName\": null, \"CountDomains\": null, \"FactorPassword\": null, \"CountWindowsPhoneDevices\": null, \"MultiplexedRealAccount2ID\": null, \"MfaInitiator\": null, \"DatabaseInstanceName\": null, \"MobileAppType\": null, \"AuditId\": null, \"EventParm\": null, \"DatabaseFQDN\": null, \"Initiator\": null, \"CountServices\": null, \"Message\": null, \"EndpointOnPremise\": null, \"PrincipalName\": null, \"JobUtcScheduledTime\": null, \"Guid\": null, \"DeleteReason\": null, \"MfaReason\": null, \"DSName\": null, \"AuthorityType\": null, \"FactorCt\": null, \"PartialNewLicenseKey\": null, \"DatabaseClass\": null, \"MultiplexedRealAccount1ID\": null, \"Entity\": null, \"AggregationDate\": null, \"Change\": null, \"OldAppKey\": null, \"JobResourceName\": null, \"Trustee\": null, \"ForGlobalTenant\": null, \"UrlPath\": null, \"Duration\": null, \"Permissions\": null, \"Classification\": null, \"Managed\": null, \"ErrorMessage\": null, \"RedirectedUserUuid\": null, \"IsPasswordChange\": null, \"MessageID\": null, \"FactorOtherLocalized\": null, \"TunneledUriScheme\": null, \"UriCount\": null, \"RegularUserCostPerHour\": null, \"ActualStartLatencyMs\": null, \"Filename\": null, \"ServiceName\": null, \"FailedMessage\": null, \"TemplateName\": null, \"SyncResultReason\": null, \"MultiplexedRealAccount2Name\": null, \"ServiceType\": null, \"SourceUuid\": null, \"Format\": null, \"CountIOSDevices\": null, \"AwsCustomerId\": null, \"AppName\": null, \"SetPath\": null, \"LicenseType\": null, \"ElapsedTime\": null, \"StateDeleteType\": null, \"AgentFeatures\": null, \"CountAppLaunch\": null, \"ChainID\": null, \"State\": null, \"Path\": null, \"InternalDeviceType\": null, \"EmailAddress\": null, \"TotalADUserCount\": null, \"History\": null, \"IsSwsEnabled\": null, \"AppUrl\": null, \"Role\": null, \"SourcePodFqdn\": null, \"Organization\": null, \"CountIPods\": null, \"ComputerFQDN\": null, \"CountRdpSessions\": null, \"Upgrade\": null, \"UtcScheduledTime\": null, \"RegularUsersCount\": null, \"FactorU2f\": null, \"SyncAction\": null, \"BlacklistedComputerName\": null, \"Uuid\": null, \"Online\": null, \"ResponseElapsedMs\": null, \"JobUniqueId\": null, \"WebAppTypeDisplayName\": null, \"Success\": null, \"NotSelfService\": null, \"AdminUserCostPerHour\": null, \"Session\": null, \"ContentType\": null, \"ChallengeId\": null, \"Alias\": null, \"PodName\": null, \"RetiredBy\": null, \"Profiles\": null, \"CountSimulatorDevices\": null, \"InitiatorLocalized\": null, \"TargetPrincipalNotes\": null, \"ApplicationRunAccountType\": null, \"RedirectedUser\": null, \"TargetPrincipalName\": null, \"ActionPrincipalName\": null, \"HostAddress\": null, \"ClientAddress\": null, \"DiscoveryProfileName\": null, \"RecurWeekInterval\": null, \"PasswordStorageFromLocation\": null, \"FactorOther\": null, \"LiveTenantsCount\": null, \"ProfileName\": null, \"OldUuid\": null, \"IsScimProvisioningEnabled\": null, \"FailUserName\": null, \"UserQuestions\": null, \"InitiatorNotes\": null, \"Forest\": null, \"PreviousEntity\": null, \"RoleId\": null, \"To\": null, \"OwnerUuid\": null, \"PolicyModifier\": null, \"SafeName\": null, \"TotalQuestions\": null, \"WebAppType\": null, \"NewValue\": null, \"IntelRiskScore\": null, \"FailureMessage\": null, \"FactorSecurityQuestionLocalized\": null, \"AccountLockoutTime\": null, \"PasswordStorageLocation\": null, \"ContentLength\": null, \"Mechanism\": null, \"Version\": null, \"SubscriptionID\": null, \"TotalCusUserCount\": null, \"CJoinedServerCostPerHour\": null, \"FactorSmsLocalized\": null, \"JobTypeName\": null, \"DiscoveryProfileID\": null, \"GetCurrentPassword\": null, \"AgentName\": null, \"CountLiveDevices\": null, \"NewEntity\": null, \"MemberName\": null, \"NumDenyAdd\": null, \"FactorSecurityQuestion\": null, \"EditType\": null, \"SessionUser\": null, \"LocalAccountUuid\": null, \"Port\": null, \"ParentPath\": null, \"SourceType\": null, \"CountRoles\": null, \"SourceUpn\": null, \"JobSubStatus\": null, \"ProfileId\": null, \"ApplicationID\": null, \"CountDatabases\": null, \"UpdatedAttributes\": null, \"CountAfwEnrolled\": null, \"ActorName\": null, \"IsViewCredsEnabled\": null, \"UserType\": null, \"CountUnknownUsingTenantSpecificUrl\": null, \"Exception\": null, \"ShadowAppKey\": null, \"EndpointKnown\": null, \"AccountName\": null, \"Script\": null, \"AuthorityName\": null, \"CustomerCountry\": null, \"RawEvent\": null, \"NewTenantId\": null, \"SourceName\": null, \"ImpersonateTargetName\": null, \"NewOwnerUuid\": null, \"TransferredFoldersCount\": null, \"AuthorityID\": null, \"AuthMethod\": \"None\", \"Tenant\": \"TENANT1234\", \"Scopes\": \"isp.audit.events:read\", \"InternalTrackingID\": \"00000000-0000-0000-0000-000000000003\", \"EventMessage\": \"Access token created with 'cribl_audit_app' app.\", \"RequestUserAgent\": \"Cribl-4.16.2-stage-hourly.20200101T0001-example\", \"Level\": \"Info\", \"EndTime\": \"/Date(1577854801341)/\", \"_TableName\": \"events\", \"ThreadType\": \"RestCall\", \"ID\": \"00000000-0000-0000-0000-000000000004.W03.094f.examplekey02\", \"AzRoleId\": \"WR_i-example-role-id\", \"AppId\": \"cribl_audit_app\", \"TokenType\": \"Access\", \"DirectoryServiceNameLocalized\": \"CyberArk Cloud Directory\", \"StartTime\": \"/Date(1577836781341)/\", \"FromIPAddress\": \"10.0.0.1\", \"DirectoryServiceName\": \"CDS\", \"EventType\": \"Cloud.Core.OAuthToken.Create\", \"AzDeploymentId\": \"00000000-0000-0000-0000-000000000006\", \"RequestHostName\": \"10.0.0.1\", \"DirectoryServiceUuid\": \"00000000-0000-0000-0000-000000000005\", \"RequestIsMobileDevice\": false, \"ApplicationName\": \"cribl_audit_app\", \"WhenOccurred\": \"/Date(1577836801341)/\", \"ApplicationType\": \"OAuth\", \"UserGuid\": \"00000000-0000-0000-0000-000000000007\", \"NormalizedUser\": \"svc_audit@cyberark.cloud.example\", \"ClientIPAddress\": \"10.0.0.1\", \"RequestBrowserName\": \"Other\", \"WhenLogged\": \"/Date(1577836801341)/\", \"RequestDeviceOS\": \"Unknown\", \"IsInternalApplication\": false, \"AzRoleName\": \"WebRole\"}}","_time":1577836801.341,"cribl_breaker":"CyberArk_Audit:identity_logs"}
```

## 

##
