To send events to QRadar®
from CyberArk Identity, create a user role and configure a user policy on CyberArk Identity. The QRadar user can then create a log
source in QRadar.
Important: Centrify Identity Platform is now CyberArk Identity. The DSM RPM name remains
as Centrify Identity Platform in QRadar.
Before you begin
Ensure that you have the Tenant ID and admin login details that are supplied by CyberArk.
Ensure that you have the correct user permissions for the CyberArk admin portal to complete the
following steps:
Procedure
-
Log in to your CyberArk Identity admin portal.
-
Create a CyberArk Identity user role:
-
From the navigation pane, click .
-
In the Name field, type the name for the role.
-
Select Members, and then click Add.
-
In the Add Members window, search for the user name to assign to the
role, and then select the member.
-
Click Add.
-
Select Administrative Rights, and then click
Add.
-
From the Description list, select Read Only System
Administrator.
-
Click Save.
-
Create an authentication profile:
-
From the navigation pane, click .
-
From the Platform menu, click Authentication
Profiles.
-
Click Add Profile, and then type a name for the profile in the
Profile Name field.
-
From the Challenge 1 pane in the Authentication
Mechanisms window, select Password.
-
From the Challenge Pass-Through Duration list, select 30
minutes, and then click OK. The default is 30 minutes.
Important: Do not select any options from the Challenge 2 pane in
the Authentication Mechanisms window. Select options only from the
Challenge 1 pane.
-
Configure a user policy:
-
From the navigation pane, click .
-
From the Policy Setting pane, type a name for the policy in the
Name field.
-
From the Policy Assignment pane, click Specified
Roles.
-
Click Add.
-
From the Select Role window, select the role that you created in Step 2
from the Role list, and then click Add.
-
From the Policy Settings menu, select .
-
From the Enable authentication policy controls window, select
Yes.
-
From the Default Profile pane, select the authentication profile that
you created in Step 3 from the Default Profile list.
-
Click Save.
Note: If you have difficulty when configuring CyberArk Identity to communicate with QRadar, contact your CyberArk
administrator or your CyberArk contact.