Description
The [Idira Audit](https://docs.cyberark.com/Audit/Latest/en/Content/Resources/_TopNav/cc_Home.htm) data connector enables Microsoft Sentinel to ingest security event logs and other events from the Idira Audit service via REST API. This integration helps you detect potential security risks, monitor user activity, analyze collaboration patterns, troubleshoot configuration issues, and gain deeper insights into your environment.
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
Idira Audit Service Platform
Access to perform required configurations in Idira Audit platform
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Follow the steps below to integrate Microsoft Sentinel with Idira Audit and enable centralized monitoring of system and user activities within Microsoft Sentinel. You can also refer to the [Idira Audit documentation](https://docs.cyberark.com/admin-space/latest/en/content/siem-integration/siem-export-ms-sentinel.htm?tocpath=Integrations%7CExport%20Audit%20activities%20to%20a%20SIEM%20application%7C_____2#CreateandconfigureaSIEMintegration) and follow till Step 5.
OAuth2 Server App Name
Audit API Key
Identity Endpoint
Audit API Base URL
Audit Query Filter Action (Optional)
The optional filter parameters to filter logs based on specific 'Action' values.
Audit Query Filter Application Code (Optional)
The optional filter parameters to filter logs based on specific 'ApplicationCode' values.
Audit Query Filter Audit Type (Optional)
The optional filter parameters to filter logs based on specific 'AuditType' values.
Connect to Idira Audit API to start collecting event logs in Microsoft Sentinel
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
CyberArkAuditCCPDefinition
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC