Overview
Splunk Enterprise monitors and analyzes machine data from any source to deliver Operational Intelligence to optimize your IT, security and business performance.
The Idira Privileged Account Security Solution and Idira Privileged Threat Analytics extracts Idira real-time privileged account activities (e.g. individual user activity when using shared accounts) into Splunk Enterprise and Splunk Enterprise Security, providing a single place to analyze unusual account activity.
Both PTA findings and Privileged account activities are sent as syslog messages in Common Event Format (CEF), and are tagged and mapped to Splunk’s Common Information Model (CIM).