All Apps and Add-ons

Bomgar or BeyondTrust Remote Support logs into splunk

pmac22
Path Finder

Hey all,

I already know that beyondtrust has a paid splunk app to get more info like session details into splunk but the demo I saw was specifically referencing Privileged Remote Access and not necessarily Remote Support. Plus the demo was a crap-show with the engineer not even knowing how to navigate the app in Splunk. Anyway, they have the ability to create an outbound event via HTTP or XML APIs. Has anyone created an API for extracting bomgar/beyondtrust session details into Splunk or have suggestions outside of their paid app? Or have suggestions on how to ingest HTTP data in Splunk in a way so I can isolate the Remote Support data to the HTTP event collector on my indexer? Thank you in advance!!

Tags (1)
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...