Privileged Access Manager (PAM) fails to generate specific Splunk messages (specifically eventtype=C/D/U updates) when users or targets are added, deleted, or updated on a non-master primary node.
This behavior is caused by a product defect (DE669368) related to the Logstash marker file. PAM doesn't correctly update or track the last processed audit entry on non-master nodes, preventing the Logstash JDBC connector from picking up and forwarding the specific event types to Splunk.
This defect will be resolved in PAM 4.3.2.
To get statistics on Target Application/Users that were updated/deleted/added -> you can run our Administrative Activities Report for the said time period.