# Ingesting Delinea Audit/event Logs into Elasticsearch

**URL:** <https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870>\
**Category:** Elasticsearch\
**Created:** [February 17, 2023, 9:51pm UTC](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870 "2023-02-17T21:51:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tthiry](https://avatars.discourse-cdn.com/v4/letter/t/a4c791/32.png) [@tthiry](https://discuss.elastic.co/u/tthiry)\
**Post date:** [February 17, 2023, 9:51pm UTC](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870/1 "2023-02-17T21:51:35Z")

</div>

Hello,

I am wondering if anyone has tried ingesting Delinea Secret Server logs into Elasticsearch. I'm not quite sure where to start. We are using the cloud version of both Elastic and Delinea.

Any helpful hints would be appreciated.

Thanks,  
Tony

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 20, 2023, 2:23am UTC](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870/2 "2023-02-20T02:23:02Z")

</div>

Are you asking on how to ingest them using a pipeline in Elasticsearch (ie using grok)?

Can you share an example message?

---

<div class="post-metadata">

**Author:** ![tthiry](https://avatars.discourse-cdn.com/v4/letter/t/a4c791/32.png) [@tthiry](https://discuss.elastic.co/u/tthiry)\
**Post date:** [February 20, 2023, 8:46pm UTC](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870/3 "2023-02-20T20:46:02Z")

</div>

Hello Mark,

No, I am not asking how to parse the data but rather how to get the data out of Delinea. It's not clear to me how to extract it. Is it the syslog configuration or will I need to use an API and a scheduled task to run a series of reports?

Thanks,  
Tony

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 20, 2023, 8:57pm UTC](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870/4 "2023-02-20T20:57:27Z")

</div>

You'd need to ask those more familiar with that product, we don't know it sorry.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 21, 2023, 1:58am UTC](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870/5 "2023-02-21T01:58:11Z")

</div>

> [@tthiry](#):
>
> Is it the syslog configuration or will I need to use an API and a scheduled task to run a series of reports?

You need to check in the documentation for Delinea or with the support of the tool as your question is not related to any Elastic tool.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2023, 1:58am UTC](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870/6 "2023-03-21T01:58:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
