Elastic high stable kql

CyberArk Privileged Access Security Error

Identifies the occurrence of a CyberArk Privileged Access Security (PAS) error level audit event. The event.code correlates to the CyberArk Vault Audit Action Code.

View Source

Detection Logic

data_stream.dataset:cyberarkpas.audit and event.type:error

False Positives

  • To tune this rule, add exceptions to exclude any event.code which should not trigger this rule.

Field Validations

Loading…

Comments (0)

Loading comments...