Use the CyberArk Identity User Behavior Analytics sensor

The primary purpose of the sensor is data collection. The CyberArk Identity User Behavior Analytics sensor is part of CyberArk Identity User Behavior Analytics and is an installable software package. As a general data collector, the CyberArk Identity User Behavior Analytics sensor supports the following operating environments:

  • Windows - Installation utilizes a standard wizard process.
  • Mac - Installation utilizes a standard Mac software installation wizard.

The CyberArk Identity User Behavior Analytics sensor can collect data from the following data sources:

  • Generic log files that you can write your own filter for
  • Any syslog event
  • Any Windows Event Log
  • Any application or network device log
  • Palo Alto Networks Cloud Services - Reading logging information from Palo Alto Network's Cortex Data Lake

  • Any external models, such as a scanner report or relational database

Install the CyberArk Identity User Behavior Analytics sensor

This section describes how to install the CyberArk Identity User Behavior Analytics sensor.

  1. Navigate to the CyberArk Identity User Behavior Analytics Portal.
  2. In the left-hand Navigation pane, click Settings to expand it and then click sensor from the menu.
  3. At the top of the Sensors page, click Add sensor.

    The Add sensor window appears.

  4. In the Step 1 section, locate and click the Windows download link to start the download.
  5. In the Step 2 section, follow the instructions to retrieve or create a sensor Access Token.
  6. Launch the Windows installer you downloaded.

    If a Windows security alert window appears, click Run Anyway to proceed.
  7. Complete the installation wizard by accepting the defaults.

    At the end of the installation (if you accepted the default to start the sensor after the installation completed), the Register window appears.

  8. Return to the CyberArk Identity User Behavior Analytics Portal and click API from the Navigation pane. At the top of the window, click New.

    The Add API Access Token window appears.

  9. Enter a name for the token and choose one of the Expiration options:

    • Limited - The token will expire on a designated date. Click the Expiration Time field to open a calendar. Then, navigate to the date you wish the token to expire.
    • Unlimited - The token will not expire.
  10. Click Create to obtain the token.

  11. Click the small icon to the right of the token, which copies the token to the clipboard. Then, click Done.
  12. For safe keeping, open a text editor or some other program and paste the token where you can save it.
  13. Return to the installer and paste the sensor Access Token into the field. Then, click Register.
  1. Navigate to the CyberArk Identity User Behavior Analytics Portal.
  2. In the left-hand Navigation panel, click Settings > sensor.
  3. At the top of the Sensors page, click Add sensor.

    The Add sensor window appears.

  4. In the Step 1 section, locate and click the Mac download link to start the download.
  5. In the Step 2 section, follow the instructions to create a sensor Access Token.
  6. Open the Analytics-sensor-Installer.dmg file downloaded previously and continue with the interactive installation.

    If you encounter an error preventing you from opening the .dmg file because it is from an unidentified developer, you can open it anyway from Security & Privacy preferences.

  7. Select Run Analytics sensor then click Finish when you reach the end of the interactive installation.

  8. Enter the sensor Access Token that you copied previously to register the sensor.

  9. Select Show Advanced Options and verify that the URL matches the URL for your CyberArk Identity User Behavior Analytics portal, then click Next.
  10. (Optional) Select Use custom proxy settings and enter details for your proxy server, if you are using one.

    You can also edit the proxy settings after the sensor is registered by clicking Settings... and then selecting the Proxy tab.

  11. Click Register to finish adding the sensor.

Manage the sensor

Manage a sensor Source

Update the CyberArk Identity User Behavior Analytics sensor

Repeat the installation process to update the sensor. The sensor installer detects the previous installation and suggests an update. See Install the CyberArk Identity User Behavior Analytics sensor for details.

You must stop the sensor prior to updating it.

Uninstall a CyberArk Identity User Behavior Analytics sensor

This section describes how to uninstall the CyberArk Identity User Behavior Analytics sensor.

  1. Open the sensor UI.
  2. At the bottom of the sensor window, click Stop sensor .

    The status changes from Running to Stopped.

  3. Close the UI.
  4. To verify that the sensor is, indeed, stopped, open Task Manager. Then, check the Applications and Services tabs.
  5. Navigate to the CyberArk Identity User Behavior Analytics sensor folder (the default installation location is C:\Program Files\AnalyticsSensor).
  6. Double-click the uninstall icon to start the wizard and complete the uninstall process.
  7. (Optional) To be thorough, you can also remove the conf, data, and logs folders from the CyberArk Identity User Behavior Analytics sensor folder. If you do this, also remove the Analytics folder from C:\ProgramData\CyberArk.
  1. Open the sensor UI.
  2. At the bottom of the sensor window, click Stop sensor.

    The status changes from RUNNING to STOPPED.

  3. At the top of the sensor window, click Delete, then click OK on the verification prompt.

  4. Close the sensor UI after it returns to the registration screen.
  5. Open Finder, then navigate to the Applications folder and double-click Analytics sensor Uninstaller to start the wizard and complete the uninstall process.
  6. (Optional) To be thorough, you can also remove the confdata, and logs folders from the /Applications/Analytics sensor folder.