Integrate CyberArk PTA
You can integrate CyberArk Privileged Threat Analytics (PTA) with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.
Key steps
The key steps in a CyberArk PTA integration are as follows:
- Install and configure a data collector if you haven't already done so.
- Configure CyberArk PTA to send data to the data collector.
Requirements
The following is required for CyberArk PTA configuration:
- Check the requirements for the data collector you're using by reviewing the guides at Data collectors.
Add a CyberArk PTA integration
To integrate CyberArk PTA, you must first install a Sophos XDR data collector, then configure CyberArk to send logs to it.
Install and configure a data collector
CyberArk PTA must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.
Configure logging and enable monitoring
When the data collector is ready, you can configure CyberArk PTA to send us data.
To set up event forwarding via syslog, do as follows:
-
Follow the steps in CyberArk's own guide: Send PTA syslog Records to SIEM. Be sure to configure the following data collector details:
- IP address: The Sophos XDR data collector's server IP address
- Port: 601
- Format: CEF
- syslogType: RFC3164
-
Follow the steps in CyberArk's own guide: Security Information and Event Management (SIEM) Applications.
- Create an XSL translator file to generate syslog output in the CEF format. Use this sample file from CyberArk: XSL translator file.
-
Open the
DBParm.inifile and configure the parameters as follows:- SyslogServerIP: The Sophos XDR data collector's server IP address.
- SyslogServerPort: 601.
- SyslogServerProtocol: TCP.
- SyslogMessageCodeFilter: See Recommended Action Codes for Monitoring.
- SyslogTranslatorFile: The XSL translator file you created above.
- Keep the default for all other values.
For more information, see DBPARM.ini file parameters.
Your CyberArk PTA data should now appear in the Sophos Data Lake after validation.
Configuration notes
Keep the following in mind during CyberArk PTA configuration:
- You can configure multiple instances of CyberArk to send data to Sophos via the same data collector. After you finish integration, repeat the steps in this section for your other instances of CyberArk.
Additional resources
For more information on configuring CyberArk PTA, see the following documents: