- 24 Mar 2025
- 2 Minutes to read
- Print
- DarkLight
CyberArk EPM
- Updated on 24 Mar 2025
- 2 Minutes to read
- Print
- DarkLight
CyberArk Endpoint Privilege Manager (EPM) is a security solution that helps organizations protect their endpoints from cyber threats and reduce the risk of data theft or encryption. EPM helps block and contain attacks on endpoint computers. For detailed information, please refer to the CyberArk’s official documentation.
Integration Method: API
Tables: Detection Finding (2004), Process Activity (1007)
This integration supports the following events.
Event | Description |
---|---|
Events | Retrieve raw events from EPM, according to filters. |
This integration supports the following versions.
CyberArk EPM Version | 25.2.1 |
CyberArk EPM API version | 24.9.0 |
Prerequisites
The user should have enabled Account Administrator with View Only permission and Allow to manage Sets option.
The sets should be bound to the user.
The user should have access to the DataBee console.
Configuration Overview
Create a User in the CyberArk console with the required permissions.
Add the CyberArk EPM data feed in the DataBee console with the below parameters
DataBee Parameter
Dropbox Parameter
Username
Username of the user
Password
Password of the user
Token URL <instance>
CyberArk dispatcher server name
API Base URL <instance>
CyberArk EPM instance URL
CyberArk EPM Configuration
Go to your CyberArk EPM login page and get the Dispatcher Server name as highlighted below.
Log in to CyberArk EPM console.
Get the CyberArk EPM instance URL as highlighted below.
Click on Administration.
Click on the Create > Create User button.
Fill out the required details on the form like Email and Password. Ensure that Account Administrator with View Only permission and Allow to manage Sets are checked.
This email and password will be used later while configuring data source. Click on Next.
Select View Only Set Admin as roles for each set to bound this user to each set then click on the Finish button.
Note:
After creating new user, there will be an email verification. Login to CyberArk EPM console with newly created user credentials.
Binding user to new set
Note:
This step is not required initially but if we create a new set then we must bound new set to user which we have created previously. Only Administrator user can bind newly created user to new set.
Login into CyberArk EPM console using Administrator user credentials and then click on Administration.
In the Account Management portal, you can see the list of sets as highlighted below.
Select the set which you have newly created.
Click on Bind > Change binding for Set “<new_set>”.
Update Roles to View Only Set Admin for user which we have created previously.
Click on the OK button.
DataBee Configuration
Login to the DataBee UI, navigate to Data > Data Feeds and click the Add New Data Feed button.
Search for the CyberArk EPM and click it as shown below.
Click on the API Ingest option for collection method.
Enter feed contact information and click Next.
In the configuration page, confirm the following:
Authorization Method: Token Url Auth
API Base URL: replace the <instance> with your CyberArk EPM instance URL.
Username: enter the Email Id of the user which we have created earlier.
Password: enter the Password of the user which we have created earlier.
Token URL: replace the <instance> with your CyberArk EPM dispatcher server name.
Event Types: preselected for all the event types that integration pulls.
Click Submit.
Troubleshooting Tips
Make you we have provided correct CyberArk EPM dispatcher server name and Instance URL.
If we are creating new set, then make sure we bind our user which we have created earlier to the newly created set
Make sure we do the email verification by login into CyberArk EPM console for newly created user if we are getting 401 error.