Splunkbase App Watcher

Tracks Apps & Technical Add-Ons by vendor across our monitored data sources.

Apps and Technical Add-Ons available on Splunkbase, organised by vendor — click a tab below to jump to a vendor's list.

Designed and Built by See Tah Wee
Not an official Splunk or Cisco page
Verified against live Splunkbase listings · Compiled 14 Aug 2026 · Cisco, F5 & Microsoft Cloud added 23 Sep 2026 · Auto-checked 23 Sep 2026
Apps are automatically checked against Splunkbase and updated every calendar quarter — on 1 Jan, 1 Apr, 1 Jul and 1 Oct (9:00 am Singapore time).
Alcatel 0 Splunkbase apps · 1 SC4S source
No dedicated Splunkbase app or Technical Add-On exists for Alcatel — confirmed via a live Splunkbase search. However, Alcatel switches are a recognised source in Splunk Connect for Syslog (SC4S), which routes their logs directly without needing an installed app.
# Ingestion Path Type Support Owner Data Source Type Collected Sourcetype / Config Reference Link Notes — Usage
1 Alcatel Switch (via Splunk Connect for Syslog) SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Alcatel switch syslogs — legacy BSD format, default port 514, MSG-format based filter sourcetype alcatel:switch → index netops SC4S docs No Splunkbase Add-on required — SC4S's built-in filter recognises Alcatel switch syslog and assigns alcatel:switch automatically. If a dedicated parsing TA is ever published on Splunkbase, add it here as a normal row.
AWS 7 apps
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for Amazon Web Services (AWS) Technical Add-On Splunk Supported AWS Config, EC2/EBS metadata, Inspector, CloudTrail, CloudWatch (logs/metrics/billing), S3/CloudFront/ELB access logs, generic S3/Kinesis/SQS, Amazon Security Lake 8.3.0 11 Sep 2026 app/1876 CURRENT STANDARD. Modular-input TA, CIM 5.x compatible. From v7.0.0 it has absorbed the Splunk Add-on for Amazon Security Lake (uninstall that add-on before upgrading to avoid duplication). Splunk Cloud users should also evaluate the newer Splunk Data Inputs (formerly Data Manager) onboarding flow, which co-exists with this TA.
2 Splunk App for AWS Security Dashboards App Splunk Supported Consumes data ingested by TA #1 1.3.0 7 Feb 2026 app/6311 Visualization layer: pre-built security dashboards on top of TA #1. Search-head tier; requires TA #1.
3 Splunk Add-on for AWS Security Hub Technical Add-On Splunk Supported AWS Security Hub — real-time findings 1.1.1 11 Jun 2026 app/8642 PREMIUM. Requires a subscription via "AWS Security Hub Extended." Converts real-time Security Hub events into findings/intermediate findings for Splunk Enterprise Security — separate from the general-purpose TA #1.
4 AWS Service Connectors (SOAR) SOAR Connector Splunk Supported AWS service management APIs — containment & investigative playbook actions 2.x Jul–Aug 2026 See notes For Splunk SOAR (response, not parsing). Splunk publishes this as 13 separate per-service connector apps, consolidated here for brevity: EC2 · GuardDuty · S3 · CloudTrail · IAM · Security Token Service · Athena · Systems Manager · Security Hub · Lambda · WAF V2 · Inspector · DynamoDB
5 CCX Add-on for AWS Products Technical Add-On (extension) 3rd party — CyberCX Enriches sourcetypes already ingested by TA #1 (Network Firewall, WAF, S3 VPC Flow, Macie, API Gateway Access Logs, Security Hub Custom) 1.2.9 4 Aug 2026 app/6542 Search-head-only extension adding field extraction & CIM compliance (Alert, Change, Network Traffic, Web) on top of TA #1 — does not replace it. Ingest via SQS-based S3 custom data type or syslog.
6 AWS Web Application Firewall Add-on Technical Add-On 3rd-party dev (Hurricane Labs) AWS WAF logs via Kinesis Firehose (JSON) 1.0.6 16 Dec 2025 app/4714 CIM 4.0+ compliant, Enterprise Security-ready. Includes a guide for routing AWS WAF logs to Splunk via Kinesis Firehose.
7 AWS Trusted Advisor Aggregator App 3rd-party dev (community, built on Hurricane Labs foundations) AWS Trusted Advisor recommendations across one or more accounts (cost, performance, security) 1.2.1 27 Dec 2024 app/4207 Pre-built multi-account dashboard; supports AWS Access/Secret keys, instance-profile credentials, or AssumeRole for cross-account data collection.
Note: AWS is not a recognised vendor in Splunk Connect for Syslog (SC4S) — verified against the SC4S "Known Vendors" list. AWS data sources are API/HEC-based (CloudTrail, CloudWatch, Kinesis, S3, etc.), not syslog, so SC4S provides no alternative GDI path here. Filtered out of the 25 raw Splunkbase search results: ITSI-specific content packs, a standalone DFD visualizer tool, and several low-adoption/duplicate community add-ons (0 reviews, overlapping scope with #6).
Check Point 4 Splunkbase apps · 3 SC4S sources
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Check Point Firewall SOAR Connector Splunk Supported Check Point Firewall management API — endpoint & network containment actions 4.0.0 4 Aug 2026 app/5777 For Splunk SOAR (response, not parsing): block/unblock IP, add/remove host from group, and other containment playbook actions against Check Point firewalls. FIPS compliant.
2 Check Point App for Splunk Technical Add-On Check Point (Not Supported) Firewall, endpoint, mobile & cloud logs via Check Point Log Exporter (all Check Point technologies/platforms) 1.1.6 6 Jul 2026 app/4293 CURRENT STANDARD. Primary parsing TA: CIM-compatible, integrates with Enterprise Security & SmartEvent dashboards (General Overview, Threat Prevention, Cyber Attack View), MITRE ATT&CK analytics for SandBlast malware findings. Uses Log Exporter (syslog) — see Check Point sk122323.
3 Check Point Exposure Management (Cyberint) Technical Add-On 3rd-party dev (bensa bensa) Cyberint / Argos Edge threat intelligence — alerts, attack tools, phishing & fraud detections 1.2.0 4 Aug 2026 app/7117 Fetches enriched, intelligence-driven threat data with automatic incident-status sync; ships pre-built dashboards for investigation.
4 Splunk Add-on for Check Point Log Exporter Technical Add-On Splunk LLC (Archived) Check Point Log Exporter over syslog (RFC5424) 1.2.0 15 Feb 2024 app/5478 ARCHIVED. Splunk-built TA specifically for Log Exporter syslog ingestion (sourcetype cp_log:syslog); Splunkbase lists it as an archived add-on. Use #2 (app/4293) for parsing instead — see the SC4S GDI option below for the Log Exporter transport layer.

Check Point — Additional GDI Option: Splunk Connect for Syslog (SC4S)

Check Point is a recognised vendor in Splunk Connect for Syslog (SC4S), a community syslog-routing layer that's an alternative (or complement) to HEC/modular-input based GDI. SC4S auto-assigns sourcetypes and routes events to an index — it still needs a parsing TA installed on the search head for CIM/dashboards unless noted otherwise.
# Ingestion Path Type Support Owner Data Source Type Collected Sourcetype / Config Reference Link Notes — Usage
1 Firewall OS (direct syslog) SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Native/raw firewall syslog output (no Log Exporter involved) sourcetype cp_log:fw:syslog → index netops SC4S docs No Splunkbase Add-on required — for devices sending direct syslog without Check Point's Log Exporter.
2 Log Exporter (Syslog / RFC5424) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Log Exporter output over IETF RFC5424 syslog, port 514/TCP sourcetype cp_log:syslog → index netops SC4S docs SC4S references the now-ARCHIVED #4 (app/5478); pair with #2 (app/4293) for parsing instead. SC4S notes Check Point's own Log Exporter config template was defective as of 2/1/2022 — use SC4S's corrected config.
3 Log Exporter (Splunk legacy format) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Legacy "Splunk format" Log Exporter output (non-RFC3164 conformant) sourcetype cp_log SC4S docs LEGACY — avoid for new deployments. SC4S docs explicitly recommend Log Exporter (Syslog) above instead. Pairs with #2 (app/4293).
Cisco 23 active · 7 deprecated/archived · 12 SC4S sources
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Cisco Security Cloud Technical Add-On Cisco Supported Cisco security portfolio via one add-on: Duo, Secure Firewall (FTD / eStreamer / ASA), Secure Endpoint, XDR, Secure Malware Analytics, Secure Network Analytics, Multicloud Defense, Email Threat Defense, Secure Workload, Isovalent, AI Defense, Identity Intelligence, NVM, Vulnerability Intelligence 4.1.2 17 Sep 2026 app/7404 CURRENT STANDARD. Cisco's unified security add-on: modular UX inputs, built-in health checks, CIM mappings for ES. Replaces the archived eStreamer client, Secure Firewall app, Secure Endpoint app and the deprecated Duo connector (see #24–#26).
2 Splunk Add-on for Cisco ASA Technical Add-On Splunk Supported Cisco ASA (and FTD in ASA-compatible format) firewall syslog 6.1.2 29 Jul 2026 app/1620 CURRENT STANDARD for ASA syslog parsing. CIM 5.x, used by ES & PCI. #1 also lists ASA under its Secure Firewall inputs — pick one ingestion path per device so you don't get duplicate events. See SC4S #1 below.
3 Splunk Add-on for Cisco Identity Services (ISE) Technical Add-On Splunk Supported Cisco ISE syslog — authentication, authorisation, posture, profiling 5.0.0 21 Nov 2024 app/1915 CIM-compatible ISE parsing for ES. #8 also collects ISE via API/syslog for networking use cases. CyberCX extension #22 adds more CIM coverage.
4 Splunk Add-on for Cisco ESA Technical Add-On Splunk Supported Cisco Secure Email (ESA) — textmail, HTTP, consolidated event, AMP, delivery, bounce & authentication logs 1.7.1 30 Jun 2026 app/1761 CIM-compatible email data for ES. See SC4S #4 for syslog ingestion.
5 Splunk Add-on for Cisco WSA Technical Add-On Splunk Supported Cisco Secure Web (WSA) — access logs & L4 Traffic Monitor (L4TM) logs 5.0.0 13 Dec 2024 app/1747 CIM Web / Network Traffic mapping for proxy data. Pairs with SC4S #5.
6 Splunk Add-on for Cisco UCS Technical Add-On Splunk Supported Cisco UCS Manager — faults, inventory & performance via the UCS API 4.3.3 10 Sep 2026 app/2731 For UCS Manager domains. For Intersight-managed UCS / HyperFlex, use #15 instead.
7 Cisco Talos Intelligence for Enterprise Security Cloud App Splunk Supported Cisco Talos threat intelligence — enriches ES findings 1.0.3 18 Jun 2026 app/7557 SPLUNK CLOUD ONLY. Supported only on Splunk Enterprise Security Cloud (AWS, GCP or Azure) running ES 7.3.2+. Not available for on-prem ES.
8 Cisco Enterprise Networking Add-on for Splunk (Cisco Catalyst Add-on) Technical Add-On Cisco Supported Catalyst Center (formerly DNA Center), Catalyst SD-WAN / SD-WAN Manager (vManage), ISE, Cyber Vision — API, syslog & NetFlow 4.0.35 8 Sep 2026 app/7538 CURRENT STANDARD for Cisco enterprise networking. Replaces the archived Cisco Network Data, DNA Center and Catalyst SD-WAN add-ons (#28, #29). SC4S's Cisco IOS page now references this add-on.
9 Cisco Enterprise Networking App for Splunk App Cisco Supported Uses data from #8 (plus Meraki, ThousandEyes, network-device syslog, NetFlow) 4.0.10 4 Sep 2026 app/7539 Visualisation layer: dashboards and data models for Catalyst Center, SD-WAN, ISE, Cyber Vision, Meraki & ThousandEyes. Search-head tier; install #8 first (its built-in user guide covers both).
10 Cisco Enterprise Networking NetFlow Add-on for Splunk Technical Add-On (extension) Cisco Supported Cisco enterprise IPFIX & High-Speed Logging (HSL) fields in NetFlow from Catalyst SD-WAN 4.0.0 26 Aug 2026 app/6872 Maps NetFlow collected through Splunk Stream, so Stream is required. Optional extension to #8.
11 Cisco Meraki Add-on for Splunk Technical Add-On Cisco Supported Meraki organisations via REST API polling & real-time webhooks — network, security & device-health events 3.4.0 14 Aug 2026 app/5580 CIM-compatible, includes sample dashboards. Built for API/webhook data only — Meraki syslog goes through SC4S #6 below.
12 Cisco Secure Access Add-on for Splunk Technical Add-On Cisco Supported Cisco Secure Access (SSE) and Cisco Umbrella logs 1.0.55 10 Sep 2026 app/7569 CURRENT STANDARD for Umbrella / Secure Access. Replaces the archived Umbrella add-ons (#27).
13 Cisco Secure Access App for Splunk App Cisco Supported Cloud Security APIs (Secure Access & Umbrella), Investigate API, Cloudlock CASB incidents 1.0.57 13 Jul 2026 app/5558 Dashboards on top of #12, plus Investigate lookups, destination blocking via API, app-usage visibility and Cloudlock incident management.
14 Cisco DC Networking App Cisco Supported Nexus 9000 switches, ACI (APIC) & Nexus Dashboard — via APIs 1.2.2 24 Jul 2026 app/7777 All-in-one app (UCC inputs and dashboards) using a single index. Replaces the archived ACI, Nexus 9k and Nexus Dashboard Insights add-ons/apps (#30).
15 Cisco Intersight Add-on for Splunk Technical Add-On Cisco Supported Cisco Intersight — alarms, audit logs, inventory & metrics 3.2.2 23 Sep 2026 app/7828 Includes pre-built dashboards. An older Intersight add-on (app/6482) is archived — use this one.
16 Cisco ThousandEyes App for Splunk App Cisco Supported ThousandEyes Cloud & Enterprise Agent and Endpoint test results, events & activity logs 0.9.0 24 Aug 2026 app/7719 PRE-1.0 RELEASE. Network / digital-experience monitoring with pre-built dashboards. Also feeds #9.
17 Cisco Splunk Add-on for AppDynamics Technical Add-On Splunk Works (Developer Supported) Splunk AppDynamics REST APIs — application, business-transaction & infrastructure performance, health-rule violations 3.2.1 1 May 2026 app/3471 Correlates APM data with logs/infrastructure data in Splunk; includes add-on health dashboards.
18 Cisco Service Connectors (SOAR) SOAR Connector Splunk Supported Cisco product APIs — containment, investigation & enrichment playbook actions 1.x–4.x Sep 2025 – Sep 2026 See notes For Splunk SOAR (response, not parsing). Splunk publishes 13 separate Cisco connector apps, grouped here to keep the table short: ISE · Secure Firewall · Firepower · Umbrella · Umbrella v2 · Umbrella Investigate · Secure Access · ESA · Secure Email & Web Manager · Secure Malware Analytics · Talos Intelligence · Meraki · Webex
19 Cisco Cyber Vision Splunk Add On Technical Add-On Cisco Cyber Vision team (Developer Supported) Cisco Cyber Vision OT/ICS — devices, sensors, vulnerabilities, activities, flows & events (REST API) 2.2.2 31 Aug 2026 app/5748 Pairs with the Cyber Vision Splunk App (v2.2.0, 10 Feb 2026) for dashboards; also formats data for the Splunk OT Security add-on. #8 can collect Cyber Vision too.
20 Cisco Endpoint Security Analytics (CESA) Add-On Technical Add-On Cisco (Not Supported) AnyConnect Network Visibility Module (NVM) endpoint & user flow telemetry 4.0.7 25 Jun 2025 app/4221 LICENSED. Needs a CESA endpoint licence for more than 50 AnyConnect clients (free 90-day trial). Dashboards in the CESA App (v4.0.8). New deployments should look at the NVM input in #1.
21 Cisco CDR Reporting and Analytics App Sideview (Partner) Cisco Unified Communications Manager (CUCM) call detail & call management records 8.4.5 6 Aug 2026 app/669 COMMERCIAL. 60-day trial. Call quality, volume, failed calls, huntgroups, concurrency and compliance reporting. Companion TA: app/4434.
22 CCX Unified Add-on for Cisco Firepower Technical Add-On (extension) 3rd party — CyberCX Firepower / FTD syslog and eStreamer events — improved field extraction 1.1.3 24 Aug 2025 app/5543 Search-head extension that aims for maximum CIM coverage of Firepower data. Check it against #1's built-in mappings before you add it.
23 CCX Add-on for Cisco Identity Services (ISE) Technical Add-On (extension) 3rd party — CyberCX Enriches ISE sourcetypes already ingested by #3 1.0.4 24 Aug 2025 app/6460 Search-head-only extension that improves CIM compliance on top of #3. Does not replace #3.
24 Duo Splunk Connector App Duo Security Duo activity, administrator, authentication, telephony, endpoint & Trust Monitor logs 2.1.0 2 Dec 2024 app/3504 DEPRECATED — END-OF-LIFE 31 May 2026. Duo's own listing says to move to Cisco Security Cloud (#1).
25 Cisco Secure eStreamer Client Add-On / Cisco Secure Firewall App Technical Add-On Cisco Security (Archived) Firepower / FTD eStreamer events (intrusion, connection, file, malware) 5.2.9 / 1.9.1 10 Oct 2023 / 20 Feb 2024 app/3662 · app/4388 ARCHIVED. eStreamer collection now lives in Cisco Security Cloud (#1).
26 Cisco Secure Endpoint App / CIM Add-On (formerly AMP for Endpoints) Technical Add-On Cisco Security (Archived) Secure Endpoint (AMP) events 3.0.0 / 2.1.2 7 Feb 2023 / 19 Apr 2024 app/3670 · app/3686 ARCHIVED. Use the Secure Endpoint input in #1.
27 Cisco Umbrella Add-On / Cisco Cloud Security Umbrella Add-on Technical Add-On Hurricane Labs / Cisco (Archived) Cisco Umbrella logs 1.0.7 / 1.0.33 10 Dec 2021 / 16 Nov 2023 app/3926 · app/5557 ARCHIVED. Replaced by the Cisco Secure Access Add-on (#12).
28 DEPRECATED Add-on / App for Cisco Network Data Technical Add-On Community — Mikael Bjerkeland (Archived) Cisco IOS, IOS-XE, IOS-XR, NX-OS network-device syslog 2.8.2 / 2.8.1 6 Feb 2026 / 8 Oct 2024 app/1467 · app/1352 ARCHIVED. Once the most-downloaded Cisco networking TA (130k+ downloads). Move to #8 plus SC4S #2 (sourcetype cisco:ios).
29 DEPRECATED Cisco DNA Center / Catalyst SD-WAN Add-ons & Apps Technical Add-On Cisco Systems (Archived) Catalyst Center (DNAC) & Catalyst SD-WAN (vManage) API data 1.0.7 / 3.1.1 28 Apr 2025 / 17 Jun 2025 DNAC TA · DNAC App · SD-WAN TA · SD-WAN App ARCHIVED. Merged into the Cisco Enterprise Networking Add-on & App (#8, #9).
30 Cisco ACI / Nexus 9k / Nexus Dashboard Insights Add-ons & Apps (deprecated) Technical Add-On Cisco Systems (Archived) ACI (APIC), Nexus 9000 and Nexus Dashboard Insights data 5.1.0 / 3.0.0 / 1.1.0 May – Nov 2024 ACI TA · ACI App · N9k TA · N9k App · NDI TA · NDI App ARCHIVED. Merged into Cisco DC Networking (#14).

Cisco — Categorised by Data Source

Secure Firewall (ASA / FTD)

#1 eStreamer / FTD / ASA · #2 ASA syslog parsing · #22 CyberCX extension · #25 archived

Security Cloud (Duo, XDR, Endpoint, SNA…)

#1 current standard · #7 Talos for ES Cloud · #24 / #26 legacy, migrate off

Identity — ISE

#3 syslog parsing · #23 CyberCX extension · #8 API collection · #18 SOAR actions

Email & Web

#4 ESA · #5 WSA · #12 / #13 Secure Access & Umbrella · #27 archived Umbrella

Enterprise Networking

#8 / #9 / #10 Catalyst Center, SD-WAN, NetFlow · SC4S #2 IOS/NX-OS syslog · #28 / #29 archived

Meraki

#11 API & webhooks · SC4S #6 syslog · #18 SOAR actions

Data Center & Compute

#14 Nexus / ACI / Nexus Dashboard · #6 UCS Manager · #15 Intersight · #30 archived

Observability, Collaboration & OT

#16 ThousandEyes · #17 AppDynamics · #21 CUCM CDR · #19 Cyber Vision (OT)

Key notes: Cisco now owns and supports most of its own Splunk integrations (Cisco Supported). Many older standalone add-ons have been merged into a few current ones: Cisco Security Cloud (#1) for security products, Cisco Enterprise Networking (#8/#9) for Catalyst, and Cisco DC Networking (#14) for Nexus/ACI. Splunk's free Splunk Cisco App Navigator (SCAN) (app/8566) lists 50+ Cisco integrations and checks whether data is flowing — useful for checking this list against your own environment. Left out of the 65 live and 63 archived raw Splunkbase results: apps that only mention Cisco (e.g. VulDB, Cyences, generic CDR tools for other vendors), ITSI content packs, low-adoption community tools, and a custom alert action for ISE.

Cisco — Additional GDI Option: Splunk Connect for Syslog (SC4S)

Cisco is a recognised vendor in Splunk Connect for Syslog (SC4S), a community syslog-routing layer that's an alternative (or complement) to HEC/modular-input based GDI. SC4S auto-assigns sourcetypes and routes events to an index — it still needs a parsing TA installed on the search head for CIM/dashboards unless noted otherwise.
# Ingestion Path Type Support Owner Data Source Type Collected Sourcetype / Config Reference Link Notes — Usage
1 ASA / FTD (Firepower) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) ASA, FTD, legacy FWSM & PIX syslog — legacy BSD format, default port 514, MSG-format based filter sourcetypes cisco:asa, cisco:ftd, cisco:firepower:syslog → index netfw (netids for Firepower) SC4S docs Pairs with #2 (app/1620) for parsing. FWSM and PIX are no longer supported by that add-on.
2 Cisco Networking (IOS, IOS-XE, IOS-XR, NX-OS, FX-OS, AireOS WLC, APIC/ACI) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Network-device syslog — legacy BSD format, default port 514 sourcetypes cisco:ios, cisco:xr → index netops SC4S docs SC4S points to #8 (app/7538). IOS is detected from the message itself; WLC and ACI must be identified by host/IP (update filter f_cisco_ios).
3 Identity Services Engine (ISE) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) ISE syslog — legacy BSD format, default port 514 sourcetype cisco:ise:syslog → index netauth SC4S docs Pairs with #3 (app/1915).
4 Email Security Appliance (ESA) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) ESA syslog — legacy BSD format, default port 514 sourcetypes cisco:esa:* (http, textmail, amp, authentication, cef, error_logs, antispam, system_logs…) → index email SC4S docs Pairs with #4 (app/1761). Needs vendor/product-by-source configuration (host or port).
5 Web Security Appliance (WSA) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) WSA access logs over syslog — legacy BSD format, default port 514 sourcetypes cisco:wsa:squid, cisco:wsa:squid:new → index netproxy SC4S docs Pairs with #5 (app/1747). Needs vendor/product-by-source configuration; make sure host and timestamp are in the log.
6 Meraki (MR / MX / MS) SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Meraki access point, security appliance & switch syslog sourcetypes meraki:accesspoints, meraki:securityappliances, meraki:switches, meraki → index netfw SC4S docs Meraki messages can't be told apart by content, so set known Meraki hosts or unique ports in SC4S. SC4S notes the Meraki add-on (#11) does not parse syslog.
7 Catalyst Center (DNA Center) SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Catalyst Center syslog — RFC5424, port 514 sourcetype cisco:dna → index netops SC4S docs No add-on listed by SC4S. For API data and dashboards, use #8 / #9.
8 Viptela (Catalyst SD-WAN) SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) SD-WAN device syslog — MSG-format based filter sourcetype cisco:viptela → index netops SC4S docs No add-on listed by SC4S. For SD-WAN Manager API data and dashboards, use #8 / #9.
9 Unified Communications Manager (UCM) SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) CUCM syslog — legacy BSD format, default port 514 sourcetype cisco:ucm → index ucm SC4S docs Syslog only. For CDR/CMR call analytics, see #21.
10 UCS / HyperFlex & Integrated Management Controller (IMC) SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) UCS and CIMC syslog — legacy BSD format, default port 514 sourcetypes cisco:ucs (UCS), cisco:infraops (CIMC) → index infraops SC4S docs Complements API-based #6 / #15. IMC reference: SC4S IMC docs.
11 Collaboration — Meeting Management, Meeting Server, TelePresence VCS SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Collaboration infrastructure syslog sourcetypes cisco:mm:audit, cisco:msnetops; cisco:tvcsmain SC4S docs Meeting Management and Meeting Server need vendor/product-by-source configuration. Other pages: MM · TVCS.
12 Legacy — ACS & ACE SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Access Control System and Application Control Engine syslog sourcetypes cisco:acsnetauth; cisco:acenetops SC4S docs LEGACY PRODUCTS. The ACS add-on SC4S refers to (app/1811) is archived; ISE (#3) replaced ACS. ACE: SC4S docs.
F5 6 active · 4 archived (1 row) · 1 SC4S source
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for F5 BIG-IP Technical Add-On Splunk Supported BIG-IP LTM, GTM/DNS, ASM (Advanced WAF) & APM — traffic data, system logs, settings, performance metrics & traffic statistics via syslog, iRules (HSL) and the iControl API 7.0.1 2 Sep 2026 app/2680 CURRENT STANDARD. The only actively maintained, Splunk-supported F5 parsing add-on. CIM-compatible for ES, PCI and ITSI. Pairs with SC4S #1 below for syslog transport.
2 F5 BIG-IP LTM SOAR Connector Splunk Supported BIG-IP LTM iControl API — pool & node management 2.1.5 4 Aug 2026 app/5948 For Splunk SOAR (response, not parsing): investigate and manage BIG-IP LTM pools and nodes as playbook actions.
3 Splunk Add-on for NGINX Technical Add-On Splunk Supported NGINX (an F5 product) web server access & error logs and performance metrics — file monitoring & API inputs 3.3.2 10 Sep 2026 app/3258 Listed here because F5 owns NGINX. CIM-compatible for ES, PCI and ITSI.
4 F5 XC Add-on Technical Add-On 3rd-party dev (Waleed Abosree) F5 Distributed Cloud (XC) HTTP access, WAF, Bot Defense & L7 service-policy logs via HEC (sourcetype f5:xc) 1.2.0 29 Jul 2026 app/9322 NEW / LOW ADOPTION. The only F5 Distributed Cloud parser on Splunkbase. Maps to CIM Web and Intrusion Detection. Splunkbase lists it as type "app", but it works as a TA.
5 F5 XC Monitoring App 3rd-party dev (Waleed Abosree) Uses data from #4 2.0.0 29 Jul 2026 app/9321 Dashboards only: WAF attack analytics, Bot Defense, L7 policy enforcement, threat geomap and HTTP performance. Requires #4.
6 F5 WAF Security App 3rd-party dev (Nexinto) — Not Supported F5 ASM (Advanced WAF) attack events app/2873 NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date. GeoIP, attack-type and violation dashboards for ASM data. Use #1 for ASM parsing instead.
7 F5 Networks - LTM / F5 Security / F5 Access Visibility / F5 Analytics (iApp) App F5 Networks & community (Archived) Legacy LTM, ASM and APM dashboards 2.0 / 1.0.0 Apr – Dec 2016 LTM · Security · Access · Analytics ARCHIVED — 2016. F5's own Splunk apps have been unmaintained since 2016. Use #1 for data; there is no supported F5 dashboard app to replace them.
Key notes: F5 has a small Splunkbase footprint. Almost all BIG-IP use cases (LTM, DNS/GTM, Advanced WAF/ASM, APM) come down to one Splunk-supported add-on (#1). F5 publishes no supported dashboard app of its own. Left out of the raw search results: an Atlas ITSI content pack for BIG-IP (app/7418) and an archived 2015 query tool.

F5 — Additional GDI Option: Splunk Connect for Syslog (SC4S)

F5 is a recognised vendor in Splunk Connect for Syslog (SC4S), a community syslog-routing layer that's an alternative (or complement) to HEC/modular-input based GDI. SC4S auto-assigns sourcetypes and routes events to an index — it still needs a parsing TA installed on the search head for CIM/dashboards unless noted otherwise.
# Ingestion Path Type Support Owner Data Source Type Collected Sourcetype / Config Reference Link Notes — Usage
1 BIG-IP (LTM / GTM / ASM / APM) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) BIG-IP syslog and iRule-generated events — legacy BSD format, default port 514 sourcetypes f5:bigip:syslog, f5:bigip:irule, f5:bigip:ltm:http:irule, f5:bigip:gtm:dns:request:irule, f5:bigip:asm:syslog, f5:bigip:apm:syslog, f5:bigip:ltm:access_json → index netops (netwaf for ASM) SC4S docs Pairs with #1 (app/2680). Needs vendor/product-by-source configuration, and the host must be in the syslog header. Without the f_f5_bigip filter, OS-level events fall back to nix:syslogosnix.
Linux 8 active · 6 deprecated/archived
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for Unix and Linux Technical Add-On Splunk Supported Unix/Linux OS logs, performance metrics, process/service info, package inventory, cron, hardware, network config 10.3.4 1 Sep 2026 app/833 CURRENT STANDARD. UF-based scripted/modular inputs providing rapid operational visibility across large-scale Unix/Linux fleets; pairs with the (now-archived) Splunk App for Unix and Linux dashboards. CIM 6.x compatible. v6.0 introduced default index/.conf changes — test upgrades in non-production first.
2 Splunk Add-on for Linux Technical Add-On Splunk Supported Linux performance metrics via HEC/TCP (CPU, memory, swap, disk, network, load, process, TCP connections, thermal, uptime) 2.1.1 30 Mar 2026 app/3412 Lighter-weight, metrics-only alternative to TA #1 — pushes data via HTTP Event Collector/TCP instead of UF scripted inputs. CIM 5.x compatible. Choose based on whether you need full log collection (#1) or just metrics (#2).
3 Splunk Asset and Risk Intelligence Technical Add-on For Linux Technical Add-On Splunk Supported Real-time Linux IT asset discovery & attribution (Splunk Asset and Risk Intelligence / SARI Edge Discovery) 1.2.0 17 Sep 2025 app/7416 Feeds Splunk's Asset and Risk Intelligence product — distinct from general log ingestion in TA #1/#2; focused on asset inventory/attribution.
4 Splunk Exposure Analytics Add-on for Linux Technical Add-On Splunk Supported Enriched asset & user data from Splunk forwarder endpoints (system, user, network, full-disk-encryption info) 1.0.0 29 Apr 2026 app/8692 Optional entity-discovery source for Splunk Exposure Analytics; deploy to forwarders to enhance endpoint-derived enrichment alongside other discovery sources.
5 BeyondTrust Privilege Management for Unix and Linux App BeyondTrust Corporation BeyondTrust Privilege Management — privileged command activity, recorded sessions, system-level control data 1.0.8 6 Jul 2026 app/7398 Vendor-published example app demonstrating centralized visibility into privileged access activity on Unix/Linux; provided free as a base for custom implementations.
6 Sandfly Agentless Security for Linux App Sandfly Security Sandfly agentless Linux endpoint security findings (drift detection, rootkit/intrusion checks) 4.7.0 12 Feb 2026 app/5016 Vendor-published dashboards/inputs for Sandfly's agentless Linux security scanning product. CIM 6.x compatible.
7 OCSF TA for Linux Technical Add-On (extension) 3rd-party dev (Arkitech Security) Auditd events mapped to OCSF-compliant fields (on top of TA #1's Auditd collection) 2.3.3 18 Jul 2026 app/7432 Search-head extension adding OCSF and CIM 8.x field mapping for Auditd — ties STIG/CIS compliance data to security use cases.
8 Monitoring Linux - Metrics and Logs Forwarding Technical Add-On 3rd-party dev (Outcold Solutions) Linux metrics & logs via a proprietary lightweight forwarder (alternative to UF) 5.21.411 18 Nov 2024 app/4768 Commercial alternative collection agent for environments that prefer not to deploy a full Universal Forwarder.
9 Splunk App for Unix and Linux App Splunk LLC (Archived) Consumes data ingested by TA #1 6.0.2 11 Jun 2021 app/273 ARCHIVED / EOL. Splunk officially end-of-sold this app 30 Apr 2021 and end-of-lifed it 13 Mar 2022, refocusing on IT Essentials Work and IT Service Intelligence (ITSI) instead — the same fate as the Windows Infrastructure companion app.
10 Splunk Add-on for Sysmon for Linux Technical Add-On Splunk LLC (Archived) Sysmon for Linux events 1.0.0 24 Oct 2022 app/6652 ARCHIVED. No confirmed modern replacement identified on Splunkbase for dedicated Sysmon-for-Linux parsing.
11 NMON Performance Monitor for Unix and Linux Systems App 3rd-party dev (Guilhem Marchand) NMON performance metrics (CPU, memory, disk, network) for Unix/Linux 1.9.21 30 Nov 2019 app/1753 ARCHIVED. Long-popular community performance app (49 reviews); evaluate TA #1/#2's native performance metrics as the modern equivalent.
12 Linux Auditd App 3rd-party dev (Doug Brown) Linux Auditd security events 3.1.0 18 Oct 2019 app/2642 ARCHIVED. Pair OCSF TA for Linux (#7) with TA #1's Auditd input for a modern equivalent.
13 Linux Secure Technology Add-On Technical Add-On 3rd-party dev (Doug Brown) Linux /var/log/secure authentication & authorization events 1.0.1 29 Nov 2021 app/3476 ARCHIVED. No confirmed modern replacement identified on Splunkbase specific to /var/log/secure parsing.
14 Linux Netfilter (iptables) Technology Add-On Technical Add-On 3rd-party dev (Doug Brown) Linux Netfilter/iptables firewall logs 1.0.0 2 Jul 2019 app/3089 ARCHIVED. Consider the SC4S "Generic *NIX" path below for appliance-style iptables/syslog forwarding, or TA #1 for host-based collection.
Note on SC4S: Linux/Unix is a recognised source in Splunk Connect for Syslog (SC4S) via the "Generic *NIX" base source (sourcetype nix:syslog → index osnix), pairing with TA #1 (app/833). SC4S's own documentation is explicit that this path is intended for appliances built on Linux/BSD that log via syslog — it is NOT a replacement for the Universal Forwarder on general-purpose Linux servers, which offers far more comprehensive event/metric collection for both security and operations use cases. Reference: SC4S Generic *NIX docs. Filtered out of the raw Splunkbase search results: platform-suffixed packages that aren't actually Linux data sources (e.g. "CyberArk Audit for Splunk (for Linux 64-bit)" is a CyberArk data source, not a Linux one), Python runtime packages, UF-upgrade utilities, ITSI content packs, an internal Splunk self-monitoring add-on (S.o.S), and several low-adoption/unclear community listings.
Microsoft Cloud Azure · Entra ID · Microsoft 365 · Defender — 13 active · 4 archived · 1 SC4S source
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for Microsoft Cloud Services Technical Add-On Splunk Supported Azure — Event Hubs (diagnostic, Entra ID & resource logs streamed to Event Hub), activity/audit logs, resource data, service status, Storage Table & Blob 6.3.3 10 Sep 2026 app/3110 CURRENT STANDARD for Azure. CIM-compatible for ES, PCI and ITSI. Most inputs from the Splunk Works Azure add-on (#7) have moved here — see the migration guide.
2 Splunk Add-on for Microsoft Security Technical Add-On Splunk Supported Microsoft Defender XDR (365 Defender) incidents & alerts, Defender for Endpoint alerts, Defender Advanced Hunting events 4.0.0 21 Jul 2026 app/6207 CURRENT STANDARD for Defender. Replaces the archived Microsoft 365 Defender add-on and Defender Advanced Hunting add-on (#14, #15). Dashboards are in #5.
3 Splunk Add-on for Microsoft Office 365 Technical Add-On Splunk Supported Office 365 Management Activity API — audit logs for Entra ID, SharePoint Online, Exchange Online & DLP; service status and messages; message trace 6.1.0 30 Jul 2026 app/4055 CURRENT STANDARD for Microsoft 365. Took over message trace from the archived Reporting Web Service add-on (#16).
4 Microsoft Azure App for Splunk App Splunk Works (Not Supported) Uses data from #1, #2 & #7 2.1.1 11 Dec 2024 app/4882 Dashboards for subscriptions, resources, VMs, metrics, storage, security monitoring and billing (beta), plus onboarding guides for app registrations. Search-head tier.
5 Microsoft 365 App for Splunk App Splunk Works (Not Supported) Uses data from #2, #3 & #6 3.3.2 13 Apr 2026 app/3786 Dashboards for Entra ID, Defender XDR, Defender for Endpoint, Exchange, SharePoint, OneDrive, Teams and Power BI, with a step-by-step onboarding guide. Search-head tier.
6 Microsoft Teams Add-on for Splunk Technical Add-On Splunk Works (Not Supported) Teams call records, sessions & segments (call quality — jitter, packet loss, RTT) via Microsoft Graph 2.0.1 16 Jul 2026 app/4994 Feeds the Teams dashboards in #5.
7 Splunk Add on for Microsoft Azure Technical Add-On Splunk Works (Not Supported) Entra ID users, sign-ins, directory audits, devices, groups & risk detections; Defender for Cloud (Security Center) alerts; Resource Graph 4.2.0 15 Nov 2024 app/3757 LEGACY — INPUTS MIGRATED. Its own listing says the inputs have moved to Splunk-supported add-ons (mainly #1). Plan to migrate. Still includes useful alert actions (stop VM, add user to group).
8 Microsoft O365 Email Add-on for Splunk Technical Add-On Splunk Works (Not Supported) M365 email from a dedicated compliance mailbox via Microsoft Graph — attachments, IOCs, SPF/DKIM/DMARC, phishing risk scoring 2.4.18 24 Apr 2026 app/5365 Security-focused mailbox ingestion with hashing, ZIP/macro inspection and header parsing. Separate from the audit logs in #3.
9 Microsoft Cloud Service Connectors (SOAR) SOAR Connector Splunk Supported Microsoft Graph, Entra ID, Defender, Azure & M365 APIs — containment & investigative playbook actions 1.x–4.x Sep 2025 – Sep 2026 See notes For Splunk SOAR (response, not parsing). Splunk publishes 15 separate Microsoft cloud connector apps, grouped here to keep the table short: MS Graph for Active Directory · Azure AD Graph · MS Graph for Office 365 · MS Graph for O365 – Federal · Microsoft 365 · Microsoft 365 Defender · Defender for Endpoint · Azure Compute · Azure SQL · Azure DevOps · Teams · OneDrive · MS Graph for SharePoint · EWS for Office 365 · Intune (SOAR Community)
10 Splunk Alerts for Microsoft Teams App (Alert Action) Splunk Supported Outbound only — posts Splunk alerts to Teams channels 1.1.11 27 Apr 2026 app/4855 Not a data source. Sends alert notifications to Teams (message cards, actions, retry through KV store).
11 Microsoft Graph Security Score Add-on Technical Add-On 3rd-party dev (Crossrealms) Microsoft Secure Score via the Graph Security API 1.3.0 15 Sep 2026 app/5693 Lightweight scripted input for tracking Secure Score over time.
12 Microsoft 365 Defender Threat Vulnerability Add-on for Splunk Technical Add-On 3rd-party dev (Thomas Hillesøy) Defender Vulnerability Management (TVM) — device vulnerabilities & exposure 2.0.2 17 Aug 2026 app/6470 CIM Vulnerabilities data model, plus reports that build ES asset lookups. Fills a gap: #2 does not collect TVM data.
13 MS Defender Advanced Hunting Technical Add-On (search command) 3rd-party dev (Masaki Yoshikawa) Ad-hoc KQL Advanced Hunting queries against Defender for Endpoint, Defender XDR or Graph APIs 0.2.6 8 Aug 2026 app/6456 Search-time custom command, not scheduled ingestion. Useful for pivoting from Splunk into Defender during investigations.
14 Microsoft Defender Advanced Hunting Add-on for Splunk Technical Add-On Splunk Works (Archived) Defender Advanced Hunting events (CIM Endpoint) 1.4.2 9 Jan 2026 app/5518 ARCHIVED — FINAL VERSION. Moved into #2.
15 Microsoft 365 Defender Add-on for Splunk Technical Add-On Splunk Works (Archived) 365 Defender incidents, Defender for Endpoint alerts 1.3.0 21 May 2021 app/4959 ARCHIVED. Data collection moved to #2 and dashboards to #5.
16 Splunk Add-on for Microsoft Office 365 Reporting Web Service Technical Add-On Splunk Works (Archived) Office 365 message trace 2.0.1 21 Sep 2022 app/3720 ARCHIVED. Moved into #3.
17 Microsoft Graph Security API Add-On / Microsoft Sentinel Add-On Technical Add-On Microsoft Corporation (Archived) Graph Security API alerts (inbound) / Splunk → Sentinel log forwarding (outbound) 1.2.6 / 1.0.6 7 Jun 2023 / 7 Mar 2022 app/4564 · app/5312 ARCHIVED. Microsoft-published add-ons that are no longer maintained. Use #2 for Defender alerts and #1 for Azure/Entra data.

Microsoft Cloud — Categorised by Data Source

Azure (subscriptions, resources, Event Hub)

#1 current standard · #4 dashboards · #7 legacy, migrate off · #9 SOAR (Compute, SQL, DevOps)

Entra ID (Azure AD)

#3 audit via Management API · #1 sign-in/audit via Event Hub · #9 SOAR (MS Graph for AD)

Microsoft 365 (Exchange Online, SharePoint, Teams)

#3 audit & DLP · #6 Teams call quality · #8 mailbox content · #5 dashboards

Defender XDR / Endpoint

#2 incidents, alerts & hunting · #12 vulnerabilities · #13 ad-hoc KQL · #11 Secure Score

Scope: this tab covers Microsoft's cloud services only. On-prem Windows, Active Directory, DNS and DHCP are on the Windows tab. On-prem server products — Exchange Server, SQL Server, IIS, SCOM, SCCM, Hyper-V — were left out; they have their own Splunk-supported add-ons (e.g. Exchange, IIS, SCOM) and could get their own tab later. Also left out: on-prem SOAR connectors (Exchange EWS on-prem, SCCM, SCOM, SQL Server), low-adoption community lookups (Entra group/tenant/mailbox lookups), and the archived "Blue team app for Office 365 and Azure" (app/4667).

Microsoft Cloud — Additional GDI Option: Splunk Connect for Syslog (SC4S)

Microsoft's cloud services are API-based (Graph, Management Activity API, Event Hubs), not syslog, so SC4S plays a very small part here. The SC4S "Microsoft" vendor entry covers only one product:
# Ingestion Path Type Support Owner Data Source Type Collected Sourcetype / Config Reference Link Notes — Usage
1 Defender for Cloud Apps (formerly Cloud App Security / MCAS) SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) MCAS SIEM agent output as CEF — legacy BSD format, default port 514 sourcetype cef, source microsoft:cas → index main SC4S docs The only Microsoft source in SC4S. Parsed by the generic Splunk Add-on for CEF (GitHub, not Splunkbase). Check Microsoft's current SIEM-integration guidance first — the API-based add-ons above are the main path for Microsoft cloud data.
Palo Alto Networks 10 Splunkbase apps · 4 SC4S sources
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for Palo Alto Networks Technical Add-On Splunk Supported Cortex XDR, IoT Security, Firewalls (NGFW), Panorama, Strata Logging Service 4.0.0 14 Aug 2026 app/7523 CURRENT STANDARD. Official parsing TA: modular inputs for IoT Security & Cortex XDR, CIM 5.x normalisation, health-check monitoring dashboard, latest PAN-OS support. Deploy on indexers / heavy forwarders.
2 Splunk App for Palo Alto Networks App Splunk LLC (Supported) Consumes data ingested by TA #1 (firewall, Panorama, XDR, IoT, SLS) 1.0.1 14 Nov 2024 app/7505 Visualization layer: security reporting & analysis dashboards correlating app/user activity across network & security infrastructure. Search-head tier; requires TA #1.
3 Palo Alto API Inputs Add On Technical Add-On 3rd-party dev (Edlyn Liew) Logs & telemetry from PAN devices via API (alternative to syslog/HEC) 1.0.16 4 Dec 2025 app/8283 Use where syslog forwarding isn't feasible (firewalls behind NAT / restricted networks) or extra API metadata is needed; supports custom API endpoint scripts.
4 CCX Palo Alto Cortex XDR (CEF) Technical Add-On 3rd party — CyberCX Cortex XDR syslog (CEF) forwarded from Cortex Data Lake via syslog server 1.0.2 29 Aug 2025 app/6326 Field-extraction bundle mapping XDR CEF logs to CIM datamodels: Network Traffic, Change, Malware, Alerts, IDS. Not Splunk supported.
5 Palo Alto Cortex XDR SOAR Connector SOAR Community Cortex XDR API — incidents, endpoints 1.2.1 28 Apr 2025 app/6046 For Splunk SOAR (response, not parsing): on-poll ingest, list endpoints, block/allow hash, quarantine / unquarantine device, get incident details.
6 Prisma Cloud Audit Input Technical Add-On (input) 3rd-party dev (Brett Adams) Prisma Cloud audit logs (API pull) 1.0.4 3 Aug 2026 app/6379 Pulls the Prisma Cloud audit trail into Splunk for admin / compliance visibility.
7 Add-on for Prisma Cloud Audit Technical Add-On (input) 3rd-party dev (Rotimi Akinbobola) Audit events from Prisma Cloud 2.0.1 20 Sep 2026 app/7700 Alternative Prisma Cloud audit fetcher — compare features against #6 before selecting.
8 Palo Alto Networks Add-on for Splunk (Splunk_TA_paloalto) Technical Add-On Palo Alto Networks NGFW, Panorama, Traps ESM; also Aperture / SaaS Security, Cortex XDR, MineMeld / AutoFocus 8.1.3 24 May 2024 app/2757 DEPRECATED / ARCHIVED. Legacy PAN-owned TA. Migrate to #1 (Splunk-supported); note revised CIM mapping, macros, and input config changes during migration.
9 Palo Alto Networks App for Splunk (SplunkforPaloAltoNetworks) App Palo Alto Networks Consumes legacy TA #8 data (firewall, GlobalProtect, WildFire, Traps, Aperture) 8.1.3 24 May 2024 app/491 DEPRECATED / ARCHIVED. Legacy dashboards: adversary attacks, incidents, SaaS usage, system health, config audit, malware, GlobalProtect VPN. Migrate to #2.
10 CCX Add-on for Palo Alto Networks (PAN IOT) Technical Add-On 3rd party — CyberCX IoT Security API — alert events, detections, vulnerabilities 1.0.0 27 Feb 2024 app/7250 ARCHIVED. CIM-compliant extractions (Alert, Endpoint, Network Traffic, IDS, Vulnerabilities). Superseded by the native IoT input in TA #1.

Palo Alto Networks — Categorised by Data Source

NGFW / Panorama (Syslog)

#1 current standard · #8 / #9 legacy, migrate off · #3 API-based alternative

Strata Logging Service / Cortex Data Lake

#1 native SLS input · #4 CEF-via-syslog extraction

Cortex XDR

#1 API modular input · #4 CEF syslog parsing · #5 SOAR response actions

IoT Security

#1 native input · #10 archived CyberCX alternative

Prisma Cloud

#6 / #7 audit logs. Prisma Cloud Compute (Twistlock) App — app/4555 by Palo Alto Networks — covers incidents & forensics via the Compute API (verify latest version on the listing).

Key notes: the Palo Alto App + Add-on pair (#1 + #2) is now officially Splunk Supported — all updates and support are managed by Splunk. Legacy #8 / #9 are deprecated; #10 is archived — all three are listed last in the table below. Splunkbase Classic will be deactivated on 18 Feb 2026 — update any bookmarked classic links.

Palo Alto Networks — Additional GDI Option: Splunk Connect for Syslog (SC4S)

Palo Alto Networks is a recognised vendor in Splunk Connect for Syslog (SC4S), a community syslog-routing layer that's an alternative (or complement) to HEC/modular-input based GDI. SC4S auto-assigns sourcetypes and routes events to an index — it still needs a parsing TA installed on the search head for CIM/dashboards unless noted otherwise.
# Ingestion Path Type Support Owner Data Source Type Collected Sourcetype / Config Reference Link Notes — Usage
1 PAN-OS (NGFW / Panorama / Cortex Data Lake) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) NGFW/Panorama/CDL syslog — legacy BSD default port 514, or IETF Framed on port 601 sourcetypes pan:log, pan:globalprotect, pan:traffic, pan:threat, pan:system, pan:config, pan:hipmatch, pan:correlation, pan:userid SC4S docs Alternative transport/routing layer to the direct syslog input already built into #1 (app/7523); still requires that TA on search heads for CIM parsing/dashboards. Useful if you already run SC4S for centralized syslog routing across many vendors.
2 Cortex XDR SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Cortex XDR / Cortex Data Lake syslog — requires TLS, IETF Framed, port 5425 sourcetypes pan:*, pan:xsoar SC4S docs SC4S docs still reference the deprecated #8 (app/2757) — pair with current-standard #1 (app/7523) instead for parsing.
3 Traps SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Traps ESM syslog — legacy BSD format, default port 514 sourcetype pan:traps4 SC4S docs Pairs with #1 (app/7523) for parsing.
4 Prisma SD-WAN ION SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Prisma SD-WAN ION flow, authentication & event syslogs (MSG format) sourcetypes prisma:sd-wan:flow, prisma:sd-wan:authentication, prisma:sd-wan:event SC4S docs No Splunkbase Add-on required. Distinct data source from Prisma Cloud (#6/#7, API-based audit logs) — Prisma SD-WAN ION is a separate networking product ingested purely via syslog.
Salesforce 6 apps
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for Salesforce Technical Add-On Splunk Supported Salesforce REST API — Event Log File data & SOQL object query output 7.0.1 3 Sep 2026 app/3549 CURRENT STANDARD. CIM-compatible inputs for use with Enterprise Security, PCI Compliance app, ITSI. v2.0.0 introduced breaking changes — always test upgrades in non-production before deploying.
2 Salesforce SOAR Connector Splunk Supported Salesforce object management API 3.0.1 21 Jul 2026 app/5930 For Splunk SOAR (response, not parsing): create/update/manage Salesforce objects as part of automated playbooks. FIPS compliant.
3 Splunk Add-on for Salesforce Streaming API Technical Add-On Splunk Works (Not Supported) Salesforce Streaming API — PushTopic, generic, platform & Change Data Capture (CDC) events 2.1.0 24 Jul 2026 app/5689 Near real-time push-based ingestion, complementary to #1's polled REST API collection. Not officially Splunk supported despite Splunk Works authorship.
4 CCX Extensions for Salesforce Technical Add-On (extension) 3rd party — CyberCX Enriches sourcetypes already ingested by #1 / #3 (login history, setup audit trail, log file, streaming login/report/security events) 1.0.6 24 Aug 2025 app/7174 Search-head-only extension adding field extraction & CIM compliance (Alerts, Authentication, Change, Data Access, IDS) on top of #1 and #3 — does not replace either add-on.
5 Salesforce Commerce Cloud Connector for CX Monitoring App 3rd-party dev (AIOPS Group Monitoring Team) Salesforce Commerce Cloud (SFCC) — logs, orders, products, pricebooks, inventory, eCDN, customer data 6.15.0 21 Sep 2026 app/6570 Broader CX-monitoring solution (not Salesforce CRM-specific): 360° monitoring with self-healing, 110+ real-time alerts, 200+ KPIs across the SFCC storefront stack.
6 Salesforce Monitoring App for Splunk App 3rd-party dev (Rojo Consultancy BV) Salesforce transactional & operational data (login history, platform/object stats, REST API usage) 1.0.0 24 Sep 2024 app/6579 NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date — listing shows "This app has no available versions." Out-of-the-box dashboards for login trends, org limits, and API insights once available.
Note: Salesforce is not a recognised vendor in Splunk Connect for Syslog (SC4S) — its data sources (REST/Streaming APIs) are not syslog-based, so SC4S provides no alternative GDI path here. All ingestion options above use API/HEC-based inputs instead.
Windows 10 active · 5 deprecated/archived
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for Microsoft Windows Technical Add-On Splunk Supported Windows Event Logs (Security/System/Application/etc.), performance counters, WMI, registry, Active Directory, DNS, DHCP, file system changes 11.0.2 17 Aug 2026 app/742 CURRENT STANDARD. Since v6.0.0 this TA has absorbed the standalone Splunk Add-on for Windows DNS and Splunk Add-on for Microsoft Active Directory — do not run those alongside v6.0.0+. CIM 5.x compatible. v5.0.0 introduced breaking changes — test upgrades in non-production first.
2 Splunk Asset and Risk Intelligence Technical Add-on For Windows Technical Add-On Splunk Supported Real-time Windows IT asset discovery & attribution (Splunk Asset and Risk Intelligence / SARI Edge Discovery) 1.2.0 17 Sep 2025 app/7214 Feeds Splunk's Asset and Risk Intelligence product — distinct from general log ingestion in TA #1; focused on asset inventory/attribution.
3 Windows Remote Management SOAR Connector Splunk Supported Windows Remote Management (WinRM) — remote command & script execution 3.0.1 21 Sep 2026 app/5875 For Splunk SOAR (response, not parsing): run commands/scripts on remote Windows hosts via WinRM as part of automated playbooks.
4 TA-winfw Technology Addon for Windows Firewall Technical Add-On 3rd-party dev (Andreas Roth) Windows Firewall event logs 1.0.1 21 Aug 2024 app/3300 ARCHIVED on Splunkbase (detected 23 Sep 2026). Dedicated parsing for Windows Firewall with Advanced Security logs, complementary to TA #1's general Windows Event Log coverage.
5 CCX Microsoft Windows Extensions (Defender for Endpoint and Sysmon) Technical Add-On (extension) 3rd party — CyberCX Enriches sourcetypes already ingested by TA #1 (Microsoft Defender for Endpoint & Sysmon events) 1.0.8 25 Sep 2025 app/6313 Search-head-only extension adding field extraction & CIM compliance on top of TA #1 — does not replace it.
6 Microsoft Windows Firewall Observability Technical Add-On 3rd-party dev (Amara Mohamed Traore) Windows host firewall traffic & configuration-change activity 4.0.0 25 Aug 2026 app/7790 CIM 6.x compliant; collects, parses and visualizes workstation/server firewall traffic and config changes with dedicated dashboards.
7 Windows Certificate Store Add-on for Splunk Technical Add-On 3rd-party dev (Crossrealms) Windows certificate store contents/metadata 1.0.2 22 Sep 2025 app/7013 Inventories certificates on Windows hosts for expiry tracking and compliance visibility.
8 Windows Security Operations Center App 3rd-party dev (Bojan Zdrnja) Consumes data ingested by TA #1 2.0.1 19 Sep 2025 app/647 Long-running community SOC dashboard app on top of TA #1 — correlation views for endpoint/security-relevant Windows events.
9 Add-On for Windows DNS Analytical Logging Technical Add-On 3rd-party dev (Hugh Kelley) Windows DNS Server analytical/diagnostic event logs 9 Jul 2023 app/4300 NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date. Last updated 2023 — evaluate TA #1's built-in DNS input first.
10 Windows Lateral Movement Detection Technical Add-On 3rd-party dev (community) Windows-based forensic inputs for lateral-movement threat hunting (built on SANS' 2018 "Hunt Evil" poster) 17 Sep 2025 app/4581 NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date — listing shows "This app has no available versions."
11 Splunk App for Windows Infrastructure App Splunk LLC (Archived) Consumed data from the legacy Windows TAs (superseded) 2.0.4 30 Aug 2021 app/1680 ARCHIVED / EOL. Splunk officially end-of-sold this app 31 Jul 2021 and end-of-lifed it 21 Oct 2021, refocusing on IT Essentials Work and IT Service Intelligence (ITSI) instead.
12 Splunk Add-on for Microsoft Windows DNS Technical Add-On Splunk LLC (Archived) Windows DNS Server logs 1.0.1 11 Oct 2016 app/3208 DEPRECATED / ARCHIVED. Fully absorbed into TA #1 as of v6.0.0 — do not install alongside TA #1 v6.0.0+.
13 TA for Microsoft Windows Defender Technical Add-On 3rd-party dev (Patrick O'Connell) Windows Defender antivirus/antimalware events 1.0.8 9 Dec 2021 app/3734 ARCHIVED. Consider CCX Microsoft Windows Extensions (#5) or TA #1's native Defender coverage instead.
14 Microsoft Windows DHCP addon for Splunk Technical Add-On 3rd-party dev (Nick Hills) Windows DHCP Server logs 1.2.0 17 Feb 2020 app/4359 ARCHIVED. No modern replacement identified on Splunkbase; evaluate custom inputs or generic file monitoring for DHCP server logs.
15 Splunk 5.x App for Microsoft Windows App Splunk Works (Archived) Legacy Windows infrastructure dashboards 5.0.2 12 Oct 2013 app/272 ARCHIVED — very old (2013). Long superseded by #11 and now by TA #1 + #8. Kept for historical reference only.
Note on SC4S: the SC4S "Microsoft" vendor entry covers only Cloud App Security (MCAS) — Microsoft's cloud-app CASB product, ingested as generic CEF via the Splunk Add-on for CEF, not Windows OS Event Logs. There is also an "Arcsight Microsoft Windows (CEF)" page filed under the Microfocus/ArcSight vendor category (generic CEF passthrough, no Windows-specific TA). Core Windows Event Log collection (Security/System/Application, Sysmon, etc.) is fundamentally agent-based — via Universal Forwarder + TA #1 — not syslog, since Windows has no native syslog daemon. Third-party tools (e.g. NXLog, Snare) can convert Windows Event Log to syslog for SC4S ingestion, but that is a host-side agent choice rather than a built-in SC4S "Windows" source.