PAM Not Generating Splunk Messages for User/Target Updates on Non-Master Nodes
search cancel

PAM Not Generating Splunk Messages for User/Target Updates on Non-Master Nodes

book

Article ID: 440934

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Privileged Access Manager (PAM) fails to generate specific Splunk messages (specifically eventtype=C/D/U updates) when users or targets are added, deleted, or updated on a non-master primary node.

  • Audit metrics and low-level details are forwarded correctly.
  • High-level event type messages (Create/Delete/Update) are missing from Splunk for activities on non-master nodes.
  • In some scenarios (PAM 4.3.0 and 4.3.1), these messages may also fail to send from the primary master node.

Environment

  • Product: CA Privileged Access Manager (PAM)
  • Versions: 4.2.1 --> 4.3.1
  • Feature: Splunk Integration / Logstash Forwarding

Cause

This behavior is caused by a product defect (DE669368) related to the Logstash marker file. PAM doesn't correctly update or track the last processed audit entry on non-master nodes, preventing the Logstash JDBC connector from picking up and forwarding the specific event types to Splunk.

Resolution

This defect will be resolved in PAM 4.3.2.

Additional Information

To get statistics on Target Application/Users that were updated/deleted/added -> you can run our Administrative Activities Report for the said time period.