Skip to content

Conversation

@tirthrajchaudhari-crest
Copy link
Contributor

@tirthrajchaudhari-crest tirthrajchaudhari-crest commented Dec 15, 2025

What does this PR do?

This is a initial release PR of CyberArk Endpoint Privilege Manager integration including all the required assets.
Integration Logo Source: https://upload.wikimedia.org/wikipedia/commons/thumb/e/e8/Cyberark-logo-dark.svg/1024px-Cyberark-logo-dark.svg.png

Additional Notes

  • Crawler code for this integration has been committed in its respective repo
  • OOTB detection rules JSON would be shared separately with the required teams as a part of separate repository.
  • Since during the standard attribute remapping we are not preserving the source attributes as per suggested best practices, it would result in filters using these standard attributes populating the values of other integrations as well as per current Datadog behaviour.

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • Add the qa/skip-qa label if the PR doesn't need to be tested during QA.
  • If you need to backport this PR to another branch, you can add the backport/<branch-name> label to the PR and it will automatically open a backport PR once this one is merged

@drichards-87
Copy link
Contributor

Created DOCS-12917 for Docs Team review.

@drichards-87 drichards-87 added the editorial review Waiting on a more in-depth review from a docs team editor label Dec 15, 2025
@drichards-87 drichards-87 removed their assignment Dec 15, 2025
- Password
- Confirm Password
6. Select the **Account Administrator** checkbox and choose the **View Only** option.
7. Select **Allow to manage Sets** checkbox.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
7. Select **Allow to manage Sets** checkbox.
7. Select the **Allow to Manage Sets** checkbox.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

- **Set Admin Audit Events**: Provides detailed audit records for actions carried out by EPM administrators within sets.
- **Account Admin Audit Events**: Provides detailed audit records for actions performed by account administrators.

Integrate CyberArk Endpoint Privilege Manager with Datadog to gain insights into raw events, policy adit events, set admin audit events, and account admin audit events using pre-built dashboard visualizations. Datadog uses its built-in log pipelines to parse and enrich these logs, facilitating easy search and detailed insights. Additionally, the integration can be used for Cloud SIEM detection rules for enhanced monitoring and security.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Integrate CyberArk Endpoint Privilege Manager with Datadog to gain insights into raw events, policy adit events, set admin audit events, and account admin audit events using pre-built dashboard visualizations. Datadog uses its built-in log pipelines to parse and enrich these logs, facilitating easy search and detailed insights. Additionally, the integration can be used for Cloud SIEM detection rules for enhanced monitoring and security.
Integrate CyberArk Endpoint Privilege Manager with Datadog to gain insights into raw events, policy audit events, set admin audit events, and account admin audit events using pre-built dashboard visualizations. Datadog uses its built-in log pipelines to parse and enrich these logs, facilitating easy search and detailed insights. Additionally, the integration can be used for Cloud SIEM detection rules for enhanced monitoring and security.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done


This integration ingests the following logs:

- **Raw Events**: Provides detailed records of endpoint activities captured by EPM agents, including threat detection events.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- **Raw Events**: Provides detailed records of endpoint activities captured by EPM agents, including threat detection events.
- **Raw Events**: Endpoint activities captured by EPM agents, including threat detection events.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I wanted to remove some of the repetitive language on these bullets. Feel free to reword further.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

This integration ingests the following logs:

- **Raw Events**: Provides detailed records of endpoint activities captured by EPM agents, including threat detection events.
- **Policy Audit Events**: Provides detailed audit records which gives immediate picture of policy usage on endpoints.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- **Policy Audit Events**: Provides detailed audit records which gives immediate picture of policy usage on endpoints.
- **Policy Audit Events**: Audit records of policy usage on endpoints.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done


- **Raw Events**: Provides detailed records of endpoint activities captured by EPM agents, including threat detection events.
- **Policy Audit Events**: Provides detailed audit records which gives immediate picture of policy usage on endpoints.
- **Set Admin Audit Events**: Provides detailed audit records for actions carried out by EPM administrators within sets.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- **Set Admin Audit Events**: Provides detailed audit records for actions carried out by EPM administrators within sets.
- **Set Admin Audit Events**: Actions carried out by EPM administrators within sets.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

- **Raw Events**: Provides detailed records of endpoint activities captured by EPM agents, including threat detection events.
- **Policy Audit Events**: Provides detailed audit records which gives immediate picture of policy usage on endpoints.
- **Set Admin Audit Events**: Provides detailed audit records for actions carried out by EPM administrators within sets.
- **Account Admin Audit Events**: Provides detailed audit records for actions performed by account administrators.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- **Account Admin Audit Events**: Provides detailed audit records for actions performed by account administrators.
- **Account Admin Audit Events**: Actions performed by account administrators.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

@tirthrajchaudhari-crest tirthrajchaudhari-crest changed the title DDS: CyberArk Endpoint Privilege Manager: Crawler Integration v1.0.0 [SAASINT-5127] DDS: CyberArk Endpoint Privilege Manager: Crawler Integration v1.0.0 Jan 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants