↳ GitHub sourceConnector

Idira Audit

Description

The [Idira Audit](https://docs.cyberark.com/Audit/Latest/en/Content/Resources/_TopNav/cc_Home.htm) data connector enables Microsoft Sentinel to ingest security event logs and other events from the Idira Audit service via REST API. This integration helps you detect potential security risks, monitor user activity, analyze collaboration patterns, troubleshoot configuration issues, and gain deeper insights into your environment.
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Idira Audit Service Platform
Access to perform required configurations in Idira Audit platform

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Follow the steps below to integrate Microsoft Sentinel with Idira Audit and enable centralized monitoring of system and user activities within Microsoft Sentinel. You can also refer to the [Idira Audit documentation](https://docs.cyberark.com/admin-space/latest/en/content/siem-integration/siem-export-ms-sentinel.htm?tocpath=Integrations%7CExport%20Audit%20activities%20to%20a%20SIEM%20application%7C_____2#CreateandconfigureaSIEMintegration) and follow till Step 5.
OAuth2 Server App Name
Audit API Key
Identity Endpoint
Audit API Base URL
Audit Query Filter Action (Optional)
The optional filter parameters to filter logs based on specific 'Action' values.
Audit Query Filter Application Code (Optional)
The optional filter parameters to filter logs based on specific 'ApplicationCode' values.
Audit Query Filter Audit Type (Optional)
The optional filter parameters to filter logs based on specific 'AuditType' values.
Connect to Idira Audit API to start collecting event logs in Microsoft Sentinel

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
CyberArkAuditCCPDefinition
Additional source files 2Solutions/CyberArkAudit/Data Connectors/CyberArkAudit_CCP/CyberArkAudit_DataConnectorDefinition.jsonsource ↗Solutions/CyberArkAudit/data/Solution_CyberArkAudit.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.