> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/user-guides/nl/import-records-1/import-from-cyberark.md).

# Importeren vanuit CyberArk PACLI

Accounts importeren vanuit CyberArk Safes met Microsoft PowerShell en de CyberArk PACLI-utility.

<figure><img src="https://914511346-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LSGVtOTYUIkVBoYtFvK%2Fuploads%2Fp1rub66SO3Rvd4Fod9Hh%2FImport-Keeper-Cyberark.jpg?alt=media&#x26;token=2dd2db77-c695-4c77-bcda-68974a31bdf0" alt=""><figcaption></figcaption></figure>

CyberArk bevat een command-line interface, PACLI, die rechtstreeks communiceert met de CyberArk Vault. Deze werkt met "bestanden" die zijn opgeslagen in "safes" in de vaul&#x74;*.* CyberArk kan *account\_gegevens exporteren, die CyberArk-clients zoals PrivateArk en Password Vault Web Access (PVWA) als bestanden opslaan in s*afes\_.

De onderstaande instructies gebruiken een PowerShell-script dat PACLI gebruikt om alle bestanden te exporteren die overeenkomen met een patroon. Met het standaardpatroon "\*" worden alle bestanden uit de Safe geëxporteerd. Het script haalt voor elk bestand de gebruikersnaam, het adres en het wachtwoord op; het kan echter worden geconfigureerd om ook andere velden op te halen indien nodig. Het script levert de geëxporteerde bestanden als objecten, waarna ConvertTo-CSV wordt gebruikt om deze om te zetten naar een Comma-separated Value (CSV)-indeling, zodat u ze in Keeper kunt importeren.

## Vereisten

Er zijn drie externe onderdelen nodig om het onderstaande script te gebruiken:

1. CyberArk PACLI
2. Een Vault.ini-configuratiebestand
3. Een User.ini-referentiebestand

### CyberArk PACLI

De PACLI is beschikbaar om te downloaden van de CyberArk Marketplace-website. Het is een zip-bestand dat het binaire bestand `PACLI.exe` en enkele ondersteunende bestanden bevat. Het script verwacht het pad van de *map* die het binaire bestand bevat.

### Vault.ini

Het bestand vault.ini bevat de parameters die PACLI nodig heeft om de vault te vinden en zich hierbij aan te melden. Bijvoorbeeld:

```ini
VAULT=CAMainVault
ADDRESS=10.11.12.13
PREAUTHSECUREDSESSION=YES
TRUSTSSC=YES
```

VAULT kan doorgaans op "CAMainVault" blijven staan.

ADDRESS is de hostnaam of het IP-adres van de CyberArk Vault-server.

De instellingen PREAUTHSECUREDSESSION en TRUSTSSC zijn vereist wanneer de aanmeldingsgebruiker wordt geverifieerd via LDAP (Active Directory) of RADIUS. In andere gevallen kunt u deze weglaten.

### User.ini

Het bestand User.ini heeft de INI-indeling. Het wordt echter gegenereerd met de tool `CreateCredFile.exe`, die CyberArk meelevert met enkele van zijn onderdelen. Voorbeeld: het genereren van een user.ini voor *Myuser* in het Active Directory-domein *CORP*:

```powershell
CreateCredFile.exe User.ini Password /Username Myuser /Password "MyPassw0rd!" /ExternalAuth /OSUsername CORP\Myusername
```

De nieuwste versie van de PACLI-zip bevat deze tool. Als u deze uitvoert met de parameter `/?`, worden de overige opties toegelicht die nuttig zijn in andere verificatiescenario's.

## Exporteren

Plak het volgende in een bestand met de extensie *.ps1*, bijvoorbeeld *Export-CyberArkSafeFiles.ps1*

```powershell
<#
.SYNOPSIS
Exports 'files', i.e., CyberArk Account passwords from a CyberArk Safe using PACLI.

.DESCRIPTION
Uses CyberArk's PACLI command to export files from a CyberArk Safe.
It retrieves files, their categories, and contents and exports an object for each.
It uses filepattern=* to get all files in the safe by default.
The default categories are 'Address' and 'UserName'.
#>
param (
    # The name of the 'Vault' in CyberArk, e.g., 'CAMainVault'
    [Parameter(Mandatory = $true)][string]$VaultName,
    # The name of the 'Safe' in CyberArk
    [Parameter(Mandatory = $true)][ValidateNotNullOrEmpty()][string]$SafeName,
    # The CyberArk log on user (must match credentials in the User.ini)
    [Parameter(Mandatory = $true)][ValidateNotNullOrEmpty()][string]$Username,
    # The path to the PACLI directory containing PACLI.exe
    [Parameter(Mandatory = $true)]
    [ValidateScript({ Test-Path -PathType Leaf (Join-Path $_ 'PACLI.exe') })]
    [string]$PACLIPath,
    # Arguments `findfiles` uses to generate the list of files to export
    [string[]]$FindFilesArguments = 'filepattern=*',
    # The categories to export from the files
    [Parameter()][string[]]$Categories = @('Address', 'UserName'),
    # A CyberArk Vault.ini file
    [Parameter()][ValidateScript({ Test-Path $_ -PathType Leaf })]
    [string]$VaultIniPath = 'Vault.ini',
    # A CyberArk User.ini (or .cred) file as generated by CreateCredFile.exe
    [Parameter()][ValidateScript({ Test-Path $_ -PathType Leaf })]
    [string]$UserIniPath = 'User.ini',
    # The folder in the safe to export files from--most use 'Root'
    [string]$FolderName = 'Root',
    # The session ID to use for the underlying PACLI commands
    [Parameter()][ValidateNotNullOrEmpty()][string]$SessionId,
    # ErrorAction for retrievefile errors
    [Parameter()][ValidateSet('Stop', 'Continue', 'SilentlyContinue')]
    [string]$PACLIErrorAction = 'Continue'
)

$PACLI = Join-Path $PACLIPath 'PACLI.exe' -Resolve

function Invoke-PACLI {
    param (
        [Parameter(Mandatory = $True)][string]$Command,
        [Parameter(ValueFromRemainingArguments)][string[]]$Arguments
    )
    $Executable = ".\{0}" -f (Split-Path -Leaf $PACLI)
    $CommandLine = "$Executable $Command $($Arguments -join ' ')"
    try {
        Push-Location $(Split-Path -Parent $PACLI) -StackName 'PACLI'
        $Output = (& $Executable $Command $Arguments 2>$null)
        if ($LastExitCode -eq 0) {
            $Output
        }
        else {
            switch ($PACLIErrorAction) {
                'Continue' {
                    Write-Error "'$CommandLine' exited with code $LastExitCode"
                }
                'Stop' { throw "'$CommandLine' exited with code $LastExitCode" }
            }
        }
    }
    finally {
        Pop-Location -StackName 'PACLI'
    }
}

Invoke-PACLI init

$PACLIDefaults = "vault=$VaultName", "user=$Username", "safe=$SafeName", 
"folder=$FolderName"
if ($SessionId) {
    $PACLIDefaults += "sessionId=$SessionId"
}
Invoke-PACLI default @PACLIDefaults
Invoke-PACLI definefromfile vault=$VaultName parmfile=(Resolve-Path $VaultIniPath) |
Out-Null
Invoke-PACLI logon logonfile=(Resolve-Path $UserIniPath) | Out-Null
Invoke-PACLI opensafe | Out-Null

try {
    # Create a temporary file to store the file contents during processing
    $tempFile = [IO.Path]::GetTempFileName()
    # Split the tempFile path into the folder and the filename for 'retrievefile'
    $localFolder = Split-Path $tempFile
    $localFile = Split-Path -Leaf $tempFile

    # Get the list of files in the safe
    Invoke-PACLI findfiles $FindFilesArguments 'output(name)' |
    Where-Object { $_.Trim() -ne '' } |
    ForEach-Object {
        $file = @{ Name = $_ }
        # Retrieve the file and store the contents (the password) in the file object
        Invoke-PACLI retrievefile file=$_ localfolder=$localFolder localfile=$localFile
        if ($LastExitCode -ne 0) { return }
        $file.Password = (Get-Content $tempFile).TrimEnd([Char]0) # Can be null-padded
        # Get the list of categories for the file as a quoted CSV string
        Invoke-PACLI listfilecategories file=$_ 'output(all,enclose)' |
        ForEach-Object {
            # Get the category name and value and strip the quotes
            $category = ($_ -split ',' | ForEach-Object { $_.Trim('"') })[0..1]
            # Add the category to the file object if it is on the list
            if ($category[0] -in $Categories) {
                $file[$category[0]] = $category[1]
            }
        }
        [PSCustomObject]$file
    }
}
finally {
    Remove-Item -Path $tempFile -Force
}

Invoke-PACLI closesafe vault=$VaultName user=$Username safe=$SafeName | Out-Null
Invoke-PACLI logoff vault=$VaultName user=$Username | Out-Null
Invoke-PACLI term | Out-Null
```

Pak PACLI.zip uit in dezelfde map als het script of in een submap daarvan.

Open PowerShell en ga naar de map met het script.

Voer het script uit en leid de uitvoer via een pipe naar [Export-CSV](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/export-csv) (Engels):

```powershell
.\Export-CyberArkSafeFiles.ps1 CAMainVault MySafe Myuser .\PACLI-Rls-v11.5.3 |
Export-CSV Records.csv -Delimiter "`t" -Encoding utf8 -NoHeader -UseQuotes Never
```

Het gebruik van tabtekens in plaats van komma's, de UTF-8-codering, het uitsluiten van een kopregel en het niet aanhalen van de gegevens zorgen er allemaal voor dat Keeper de gegevens correct kan importeren.

### Transformatie

Met PowerShell kunt u de gegevens verder transformeren dan alleen de opmaak als CSV. In dit meer geavanceerde voorbeeld wordt het veld "login" gemaakt door de velden Username en Address te combineren, en wordt dit veld ook gebruikt als het veld "title".

```powershell
.\Export-CyberArkSafeFiles.ps1 CAMainVault MySafe Myuser .\PACLI-Rls-v11.5.3 |
Select-Object @{l='Folder';e={$_.Name -replace "-$($_.Address)-$($_.Username)", '' }},
 @{l='Login';e={'{0}@{1}' -f $_.Username, $_.Address}}, Password |
Select-Object Folder, @{l='Title';e={$_.Login}}, Login, Password |
Export-Csv Records.csv -Delimiter "`t" -Encoding utf8 -NoHeader -UseQuotes Never
```

## Importeren

Volg de instructies onder [Tekstbestand importeren (.csv, .xls, .tsv)](/user-guides/nl/import-records-1/import-a-.csv-file.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/user-guides/nl/import-records-1/import-from-cyberark.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
