Tracks Apps & Technical Add-Ons by vendor across our monitored data sources.
Apps and Technical Add-Ons available on Splunkbase, organised by vendor — click a tab below to jump to a vendor's list.
| # | Ingestion Path | Type | Support Owner | Data Source Type Collected | Sourcetype / Config | Reference Link | Notes — Usage |
|---|---|---|---|---|---|---|---|
| 1 | Alcatel Switch (via Splunk Connect for Syslog) | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Alcatel switch syslogs — legacy BSD format, default port 514, MSG-format based filter | sourcetype alcatel:switch → index netops |
SC4S docs | No Splunkbase Add-on required — SC4S's built-in filter recognises Alcatel switch syslog and assigns alcatel:switch automatically. If a dedicated parsing TA is ever published on Splunkbase, add it here as a normal row. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for Amazon Web Services (AWS) | Technical Add-On | Splunk Supported | AWS Config, EC2/EBS metadata, Inspector, CloudTrail, CloudWatch (logs/metrics/billing), S3/CloudFront/ELB access logs, generic S3/Kinesis/SQS, Amazon Security Lake | 8.3.0 | 11 Sep 2026 | app/1876 | CURRENT STANDARD. Modular-input TA, CIM 5.x compatible. From v7.0.0 it has absorbed the Splunk Add-on for Amazon Security Lake (uninstall that add-on before upgrading to avoid duplication). Splunk Cloud users should also evaluate the newer Splunk Data Inputs (formerly Data Manager) onboarding flow, which co-exists with this TA. |
| 2 | Splunk App for AWS Security Dashboards | App | Splunk Supported | Consumes data ingested by TA #1 | 1.3.0 | 7 Feb 2026 | app/6311 | Visualization layer: pre-built security dashboards on top of TA #1. Search-head tier; requires TA #1. |
| 3 | Splunk Add-on for AWS Security Hub | Technical Add-On | Splunk Supported | AWS Security Hub — real-time findings | 1.1.1 | 11 Jun 2026 | app/8642 | PREMIUM. Requires a subscription via "AWS Security Hub Extended." Converts real-time Security Hub events into findings/intermediate findings for Splunk Enterprise Security — separate from the general-purpose TA #1. |
| 4 | AWS Service Connectors (SOAR) | SOAR Connector | Splunk Supported | AWS service management APIs — containment & investigative playbook actions | 2.x | Jul–Aug 2026 | See notes | For Splunk SOAR (response, not parsing). Splunk publishes this as 13 separate per-service connector apps, consolidated here for brevity: EC2 · GuardDuty · S3 · CloudTrail · IAM · Security Token Service · Athena · Systems Manager · Security Hub · Lambda · WAF V2 · Inspector · DynamoDB |
| 5 | CCX Add-on for AWS Products | Technical Add-On (extension) | 3rd party — CyberCX | Enriches sourcetypes already ingested by TA #1 (Network Firewall, WAF, S3 VPC Flow, Macie, API Gateway Access Logs, Security Hub Custom) | 1.2.9 | 4 Aug 2026 | app/6542 | Search-head-only extension adding field extraction & CIM compliance (Alert, Change, Network Traffic, Web) on top of TA #1 — does not replace it. Ingest via SQS-based S3 custom data type or syslog. |
| 6 | AWS Web Application Firewall Add-on | Technical Add-On | 3rd-party dev (Hurricane Labs) | AWS WAF logs via Kinesis Firehose (JSON) | 1.0.6 | 16 Dec 2025 | app/4714 | CIM 4.0+ compliant, Enterprise Security-ready. Includes a guide for routing AWS WAF logs to Splunk via Kinesis Firehose. |
| 7 | AWS Trusted Advisor Aggregator | App | 3rd-party dev (community, built on Hurricane Labs foundations) | AWS Trusted Advisor recommendations across one or more accounts (cost, performance, security) | 1.2.1 | 27 Dec 2024 | app/4207 | Pre-built multi-account dashboard; supports AWS Access/Secret keys, instance-profile credentials, or AssumeRole for cross-account data collection. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Check Point Firewall | SOAR Connector | Splunk Supported | Check Point Firewall management API — endpoint & network containment actions | 4.0.0 | 4 Aug 2026 | app/5777 | For Splunk SOAR (response, not parsing): block/unblock IP, add/remove host from group, and other containment playbook actions against Check Point firewalls. FIPS compliant. |
| 2 | Check Point App for Splunk | Technical Add-On | Check Point (Not Supported) | Firewall, endpoint, mobile & cloud logs via Check Point Log Exporter (all Check Point technologies/platforms) | 1.1.6 | 6 Jul 2026 | app/4293 | CURRENT STANDARD. Primary parsing TA: CIM-compatible, integrates with Enterprise Security & SmartEvent dashboards (General Overview, Threat Prevention, Cyber Attack View), MITRE ATT&CK analytics for SandBlast malware findings. Uses Log Exporter (syslog) — see Check Point sk122323. |
| 3 | Check Point Exposure Management (Cyberint) | Technical Add-On | 3rd-party dev (bensa bensa) | Cyberint / Argos Edge threat intelligence — alerts, attack tools, phishing & fraud detections | 1.2.0 | 4 Aug 2026 | app/7117 | Fetches enriched, intelligence-driven threat data with automatic incident-status sync; ships pre-built dashboards for investigation. |
| 4 | Splunk Add-on for Check Point Log Exporter | Technical Add-On | Splunk LLC (Archived) | Check Point Log Exporter over syslog (RFC5424) | 1.2.0 | 15 Feb 2024 | app/5478 | ARCHIVED. Splunk-built TA specifically for Log Exporter syslog ingestion (sourcetype cp_log:syslog); Splunkbase lists it as an archived add-on. Use #2 (app/4293) for parsing instead — see the SC4S GDI option below for the Log Exporter transport layer. |
| # | Ingestion Path | Type | Support Owner | Data Source Type Collected | Sourcetype / Config | Reference Link | Notes — Usage |
|---|---|---|---|---|---|---|---|
| 1 | Firewall OS (direct syslog) | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Native/raw firewall syslog output (no Log Exporter involved) | sourcetype cp_log:fw:syslog → index netops |
SC4S docs | No Splunkbase Add-on required — for devices sending direct syslog without Check Point's Log Exporter. |
| 2 | Log Exporter (Syslog / RFC5424) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Log Exporter output over IETF RFC5424 syslog, port 514/TCP | sourcetype cp_log:syslog → index netops |
SC4S docs | SC4S references the now-ARCHIVED #4 (app/5478); pair with #2 (app/4293) for parsing instead. SC4S notes Check Point's own Log Exporter config template was defective as of 2/1/2022 — use SC4S's corrected config. |
| 3 | Log Exporter (Splunk legacy format) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Legacy "Splunk format" Log Exporter output (non-RFC3164 conformant) | sourcetype cp_log |
SC4S docs | LEGACY — avoid for new deployments. SC4S docs explicitly recommend Log Exporter (Syslog) above instead. Pairs with #2 (app/4293). |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Cisco Security Cloud | Technical Add-On | Cisco Supported | Cisco security portfolio via one add-on: Duo, Secure Firewall (FTD / eStreamer / ASA), Secure Endpoint, XDR, Secure Malware Analytics, Secure Network Analytics, Multicloud Defense, Email Threat Defense, Secure Workload, Isovalent, AI Defense, Identity Intelligence, NVM, Vulnerability Intelligence | 4.1.2 | 17 Sep 2026 | app/7404 | CURRENT STANDARD. Cisco's unified security add-on: modular UX inputs, built-in health checks, CIM mappings for ES. Replaces the archived eStreamer client, Secure Firewall app, Secure Endpoint app and the deprecated Duo connector (see #24–#26). |
| 2 | Splunk Add-on for Cisco ASA | Technical Add-On | Splunk Supported | Cisco ASA (and FTD in ASA-compatible format) firewall syslog | 6.1.2 | 29 Jul 2026 | app/1620 | CURRENT STANDARD for ASA syslog parsing. CIM 5.x, used by ES & PCI. #1 also lists ASA under its Secure Firewall inputs — pick one ingestion path per device so you don't get duplicate events. See SC4S #1 below. |
| 3 | Splunk Add-on for Cisco Identity Services (ISE) | Technical Add-On | Splunk Supported | Cisco ISE syslog — authentication, authorisation, posture, profiling | 5.0.0 | 21 Nov 2024 | app/1915 | CIM-compatible ISE parsing for ES. #8 also collects ISE via API/syslog for networking use cases. CyberCX extension #22 adds more CIM coverage. |
| 4 | Splunk Add-on for Cisco ESA | Technical Add-On | Splunk Supported | Cisco Secure Email (ESA) — textmail, HTTP, consolidated event, AMP, delivery, bounce & authentication logs | 1.7.1 | 30 Jun 2026 | app/1761 | CIM-compatible email data for ES. See SC4S #4 for syslog ingestion. |
| 5 | Splunk Add-on for Cisco WSA | Technical Add-On | Splunk Supported | Cisco Secure Web (WSA) — access logs & L4 Traffic Monitor (L4TM) logs | 5.0.0 | 13 Dec 2024 | app/1747 | CIM Web / Network Traffic mapping for proxy data. Pairs with SC4S #5. |
| 6 | Splunk Add-on for Cisco UCS | Technical Add-On | Splunk Supported | Cisco UCS Manager — faults, inventory & performance via the UCS API | 4.3.3 | 10 Sep 2026 | app/2731 | For UCS Manager domains. For Intersight-managed UCS / HyperFlex, use #15 instead. |
| 7 | Cisco Talos Intelligence for Enterprise Security Cloud | App | Splunk Supported | Cisco Talos threat intelligence — enriches ES findings | 1.0.3 | 18 Jun 2026 | app/7557 | SPLUNK CLOUD ONLY. Supported only on Splunk Enterprise Security Cloud (AWS, GCP or Azure) running ES 7.3.2+. Not available for on-prem ES. |
| 8 | Cisco Enterprise Networking Add-on for Splunk (Cisco Catalyst Add-on) | Technical Add-On | Cisco Supported | Catalyst Center (formerly DNA Center), Catalyst SD-WAN / SD-WAN Manager (vManage), ISE, Cyber Vision — API, syslog & NetFlow | 4.0.35 | 8 Sep 2026 | app/7538 | CURRENT STANDARD for Cisco enterprise networking. Replaces the archived Cisco Network Data, DNA Center and Catalyst SD-WAN add-ons (#28, #29). SC4S's Cisco IOS page now references this add-on. |
| 9 | Cisco Enterprise Networking App for Splunk | App | Cisco Supported | Uses data from #8 (plus Meraki, ThousandEyes, network-device syslog, NetFlow) | 4.0.10 | 4 Sep 2026 | app/7539 | Visualisation layer: dashboards and data models for Catalyst Center, SD-WAN, ISE, Cyber Vision, Meraki & ThousandEyes. Search-head tier; install #8 first (its built-in user guide covers both). |
| 10 | Cisco Enterprise Networking NetFlow Add-on for Splunk | Technical Add-On (extension) | Cisco Supported | Cisco enterprise IPFIX & High-Speed Logging (HSL) fields in NetFlow from Catalyst SD-WAN | 4.0.0 | 26 Aug 2026 | app/6872 | Maps NetFlow collected through Splunk Stream, so Stream is required. Optional extension to #8. |
| 11 | Cisco Meraki Add-on for Splunk | Technical Add-On | Cisco Supported | Meraki organisations via REST API polling & real-time webhooks — network, security & device-health events | 3.4.0 | 14 Aug 2026 | app/5580 | CIM-compatible, includes sample dashboards. Built for API/webhook data only — Meraki syslog goes through SC4S #6 below. |
| 12 | Cisco Secure Access Add-on for Splunk | Technical Add-On | Cisco Supported | Cisco Secure Access (SSE) and Cisco Umbrella logs | 1.0.55 | 10 Sep 2026 | app/7569 | CURRENT STANDARD for Umbrella / Secure Access. Replaces the archived Umbrella add-ons (#27). |
| 13 | Cisco Secure Access App for Splunk | App | Cisco Supported | Cloud Security APIs (Secure Access & Umbrella), Investigate API, Cloudlock CASB incidents | 1.0.57 | 13 Jul 2026 | app/5558 | Dashboards on top of #12, plus Investigate lookups, destination blocking via API, app-usage visibility and Cloudlock incident management. |
| 14 | Cisco DC Networking | App | Cisco Supported | Nexus 9000 switches, ACI (APIC) & Nexus Dashboard — via APIs | 1.2.2 | 24 Jul 2026 | app/7777 | All-in-one app (UCC inputs and dashboards) using a single index. Replaces the archived ACI, Nexus 9k and Nexus Dashboard Insights add-ons/apps (#30). |
| 15 | Cisco Intersight Add-on for Splunk | Technical Add-On | Cisco Supported | Cisco Intersight — alarms, audit logs, inventory & metrics | 3.2.2 | 23 Sep 2026 | app/7828 | Includes pre-built dashboards. An older Intersight add-on (app/6482) is archived — use this one. |
| 16 | Cisco ThousandEyes App for Splunk | App | Cisco Supported | ThousandEyes Cloud & Enterprise Agent and Endpoint test results, events & activity logs | 0.9.0 | 24 Aug 2026 | app/7719 | PRE-1.0 RELEASE. Network / digital-experience monitoring with pre-built dashboards. Also feeds #9. |
| 17 | Cisco Splunk Add-on for AppDynamics | Technical Add-On | Splunk Works (Developer Supported) | Splunk AppDynamics REST APIs — application, business-transaction & infrastructure performance, health-rule violations | 3.2.1 | 1 May 2026 | app/3471 | Correlates APM data with logs/infrastructure data in Splunk; includes add-on health dashboards. |
| 18 | Cisco Service Connectors (SOAR) | SOAR Connector | Splunk Supported | Cisco product APIs — containment, investigation & enrichment playbook actions | 1.x–4.x | Sep 2025 – Sep 2026 | See notes | For Splunk SOAR (response, not parsing). Splunk publishes 13 separate Cisco connector apps, grouped here to keep the table short: ISE · Secure Firewall · Firepower · Umbrella · Umbrella v2 · Umbrella Investigate · Secure Access · ESA · Secure Email & Web Manager · Secure Malware Analytics · Talos Intelligence · Meraki · Webex |
| 19 | Cisco Cyber Vision Splunk Add On | Technical Add-On | Cisco Cyber Vision team (Developer Supported) | Cisco Cyber Vision OT/ICS — devices, sensors, vulnerabilities, activities, flows & events (REST API) | 2.2.2 | 31 Aug 2026 | app/5748 | Pairs with the Cyber Vision Splunk App (v2.2.0, 10 Feb 2026) for dashboards; also formats data for the Splunk OT Security add-on. #8 can collect Cyber Vision too. |
| 20 | Cisco Endpoint Security Analytics (CESA) Add-On | Technical Add-On | Cisco (Not Supported) | AnyConnect Network Visibility Module (NVM) endpoint & user flow telemetry | 4.0.7 | 25 Jun 2025 | app/4221 | LICENSED. Needs a CESA endpoint licence for more than 50 AnyConnect clients (free 90-day trial). Dashboards in the CESA App (v4.0.8). New deployments should look at the NVM input in #1. |
| 21 | Cisco CDR Reporting and Analytics | App | Sideview (Partner) | Cisco Unified Communications Manager (CUCM) call detail & call management records | 8.4.5 | 6 Aug 2026 | app/669 | COMMERCIAL. 60-day trial. Call quality, volume, failed calls, huntgroups, concurrency and compliance reporting. Companion TA: app/4434. |
| 22 | CCX Unified Add-on for Cisco Firepower | Technical Add-On (extension) | 3rd party — CyberCX | Firepower / FTD syslog and eStreamer events — improved field extraction | 1.1.3 | 24 Aug 2025 | app/5543 | Search-head extension that aims for maximum CIM coverage of Firepower data. Check it against #1's built-in mappings before you add it. |
| 23 | CCX Add-on for Cisco Identity Services (ISE) | Technical Add-On (extension) | 3rd party — CyberCX | Enriches ISE sourcetypes already ingested by #3 | 1.0.4 | 24 Aug 2025 | app/6460 | Search-head-only extension that improves CIM compliance on top of #3. Does not replace #3. |
| 24 | Duo Splunk Connector | App | Duo Security | Duo activity, administrator, authentication, telephony, endpoint & Trust Monitor logs | 2.1.0 | 2 Dec 2024 | app/3504 | DEPRECATED — END-OF-LIFE 31 May 2026. Duo's own listing says to move to Cisco Security Cloud (#1). |
| 25 | Cisco Secure eStreamer Client Add-On / Cisco Secure Firewall App | Technical Add-On | Cisco Security (Archived) | Firepower / FTD eStreamer events (intrusion, connection, file, malware) | 5.2.9 / 1.9.1 | 10 Oct 2023 / 20 Feb 2024 | app/3662 · app/4388 | ARCHIVED. eStreamer collection now lives in Cisco Security Cloud (#1). |
| 26 | Cisco Secure Endpoint App / CIM Add-On (formerly AMP for Endpoints) | Technical Add-On | Cisco Security (Archived) | Secure Endpoint (AMP) events | 3.0.0 / 2.1.2 | 7 Feb 2023 / 19 Apr 2024 | app/3670 · app/3686 | ARCHIVED. Use the Secure Endpoint input in #1. |
| 27 | Cisco Umbrella Add-On / Cisco Cloud Security Umbrella Add-on | Technical Add-On | Hurricane Labs / Cisco (Archived) | Cisco Umbrella logs | 1.0.7 / 1.0.33 | 10 Dec 2021 / 16 Nov 2023 | app/3926 · app/5557 | ARCHIVED. Replaced by the Cisco Secure Access Add-on (#12). |
| 28 | DEPRECATED Add-on / App for Cisco Network Data | Technical Add-On | Community — Mikael Bjerkeland (Archived) | Cisco IOS, IOS-XE, IOS-XR, NX-OS network-device syslog | 2.8.2 / 2.8.1 | 6 Feb 2026 / 8 Oct 2024 | app/1467 · app/1352 | ARCHIVED. Once the most-downloaded Cisco networking TA (130k+ downloads). Move to #8 plus SC4S #2 (sourcetype cisco:ios). |
| 29 | DEPRECATED Cisco DNA Center / Catalyst SD-WAN Add-ons & Apps | Technical Add-On | Cisco Systems (Archived) | Catalyst Center (DNAC) & Catalyst SD-WAN (vManage) API data | 1.0.7 / 3.1.1 | 28 Apr 2025 / 17 Jun 2025 | DNAC TA · DNAC App · SD-WAN TA · SD-WAN App | ARCHIVED. Merged into the Cisco Enterprise Networking Add-on & App (#8, #9). |
| 30 | Cisco ACI / Nexus 9k / Nexus Dashboard Insights Add-ons & Apps (deprecated) | Technical Add-On | Cisco Systems (Archived) | ACI (APIC), Nexus 9000 and Nexus Dashboard Insights data | 5.1.0 / 3.0.0 / 1.1.0 | May – Nov 2024 | ACI TA · ACI App · N9k TA · N9k App · NDI TA · NDI App | ARCHIVED. Merged into Cisco DC Networking (#14). |
#1 eStreamer / FTD / ASA · #2 ASA syslog parsing · #22 CyberCX extension · #25 archived
#1 current standard · #7 Talos for ES Cloud · #24 / #26 legacy, migrate off
#3 syslog parsing · #23 CyberCX extension · #8 API collection · #18 SOAR actions
#4 ESA · #5 WSA · #12 / #13 Secure Access & Umbrella · #27 archived Umbrella
#8 / #9 / #10 Catalyst Center, SD-WAN, NetFlow · SC4S #2 IOS/NX-OS syslog · #28 / #29 archived
#11 API & webhooks · SC4S #6 syslog · #18 SOAR actions
#14 Nexus / ACI / Nexus Dashboard · #6 UCS Manager · #15 Intersight · #30 archived
#16 ThousandEyes · #17 AppDynamics · #21 CUCM CDR · #19 Cyber Vision (OT)
| # | Ingestion Path | Type | Support Owner | Data Source Type Collected | Sourcetype / Config | Reference Link | Notes — Usage |
|---|---|---|---|---|---|---|---|
| 1 | ASA / FTD (Firepower) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | ASA, FTD, legacy FWSM & PIX syslog — legacy BSD format, default port 514, MSG-format based filter | sourcetypes cisco:asa, cisco:ftd, cisco:firepower:syslog → index netfw (netids for Firepower) |
SC4S docs | Pairs with #2 (app/1620) for parsing. FWSM and PIX are no longer supported by that add-on. |
| 2 | Cisco Networking (IOS, IOS-XE, IOS-XR, NX-OS, FX-OS, AireOS WLC, APIC/ACI) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Network-device syslog — legacy BSD format, default port 514 | sourcetypes cisco:ios, cisco:xr → index netops |
SC4S docs | SC4S points to #8 (app/7538). IOS is detected from the message itself; WLC and ACI must be identified by host/IP (update filter f_cisco_ios). |
| 3 | Identity Services Engine (ISE) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | ISE syslog — legacy BSD format, default port 514 | sourcetype cisco:ise:syslog → index netauth |
SC4S docs | Pairs with #3 (app/1915). |
| 4 | Email Security Appliance (ESA) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | ESA syslog — legacy BSD format, default port 514 | sourcetypes cisco:esa:* (http, textmail, amp, authentication, cef, error_logs, antispam, system_logs…) → index email |
SC4S docs | Pairs with #4 (app/1761). Needs vendor/product-by-source configuration (host or port). |
| 5 | Web Security Appliance (WSA) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | WSA access logs over syslog — legacy BSD format, default port 514 | sourcetypes cisco:wsa:squid, cisco:wsa:squid:new → index netproxy |
SC4S docs | Pairs with #5 (app/1747). Needs vendor/product-by-source configuration; make sure host and timestamp are in the log. |
| 6 | Meraki (MR / MX / MS) | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Meraki access point, security appliance & switch syslog | sourcetypes meraki:accesspoints, meraki:securityappliances, meraki:switches, meraki → index netfw |
SC4S docs | Meraki messages can't be told apart by content, so set known Meraki hosts or unique ports in SC4S. SC4S notes the Meraki add-on (#11) does not parse syslog. |
| 7 | Catalyst Center (DNA Center) | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Catalyst Center syslog — RFC5424, port 514 | sourcetype cisco:dna → index netops |
SC4S docs | No add-on listed by SC4S. For API data and dashboards, use #8 / #9. |
| 8 | Viptela (Catalyst SD-WAN) | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | SD-WAN device syslog — MSG-format based filter | sourcetype cisco:viptela → index netops |
SC4S docs | No add-on listed by SC4S. For SD-WAN Manager API data and dashboards, use #8 / #9. |
| 9 | Unified Communications Manager (UCM) | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | CUCM syslog — legacy BSD format, default port 514 | sourcetype cisco:ucm → index ucm |
SC4S docs | Syslog only. For CDR/CMR call analytics, see #21. |
| 10 | UCS / HyperFlex & Integrated Management Controller (IMC) | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | UCS and CIMC syslog — legacy BSD format, default port 514 | sourcetypes cisco:ucs (UCS), cisco:infraops (CIMC) → index infraops |
SC4S docs | Complements API-based #6 / #15. IMC reference: SC4S IMC docs. |
| 11 | Collaboration — Meeting Management, Meeting Server, TelePresence VCS | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Collaboration infrastructure syslog | sourcetypes cisco:mm:audit, cisco:ms → netops; cisco:tvcs → main |
SC4S docs | Meeting Management and Meeting Server need vendor/product-by-source configuration. Other pages: MM · TVCS. |
| 12 | Legacy — ACS & ACE | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Access Control System and Application Control Engine syslog | sourcetypes cisco:acs → netauth; cisco:ace → netops |
SC4S docs | LEGACY PRODUCTS. The ACS add-on SC4S refers to (app/1811) is archived; ISE (#3) replaced ACS. ACE: SC4S docs. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for F5 BIG-IP | Technical Add-On | Splunk Supported | BIG-IP LTM, GTM/DNS, ASM (Advanced WAF) & APM — traffic data, system logs, settings, performance metrics & traffic statistics via syslog, iRules (HSL) and the iControl API | 7.0.1 | 2 Sep 2026 | app/2680 | CURRENT STANDARD. The only actively maintained, Splunk-supported F5 parsing add-on. CIM-compatible for ES, PCI and ITSI. Pairs with SC4S #1 below for syslog transport. |
| 2 | F5 BIG-IP LTM | SOAR Connector | Splunk Supported | BIG-IP LTM iControl API — pool & node management | 2.1.5 | 4 Aug 2026 | app/5948 | For Splunk SOAR (response, not parsing): investigate and manage BIG-IP LTM pools and nodes as playbook actions. |
| 3 | Splunk Add-on for NGINX | Technical Add-On | Splunk Supported | NGINX (an F5 product) web server access & error logs and performance metrics — file monitoring & API inputs | 3.3.2 | 10 Sep 2026 | app/3258 | Listed here because F5 owns NGINX. CIM-compatible for ES, PCI and ITSI. |
| 4 | F5 XC Add-on | Technical Add-On | 3rd-party dev (Waleed Abosree) | F5 Distributed Cloud (XC) HTTP access, WAF, Bot Defense & L7 service-policy logs via HEC (sourcetype f5:xc) |
1.2.0 | 29 Jul 2026 | app/9322 | NEW / LOW ADOPTION. The only F5 Distributed Cloud parser on Splunkbase. Maps to CIM Web and Intrusion Detection. Splunkbase lists it as type "app", but it works as a TA. |
| 5 | F5 XC Monitoring | App | 3rd-party dev (Waleed Abosree) | Uses data from #4 | 2.0.0 | 29 Jul 2026 | app/9321 | Dashboards only: WAF attack analytics, Bot Defense, L7 policy enforcement, threat geomap and HTTP performance. Requires #4. |
| 6 | F5 WAF Security | App | 3rd-party dev (Nexinto) — Not Supported | F5 ASM (Advanced WAF) attack events | — | — | app/2873 | NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date. GeoIP, attack-type and violation dashboards for ASM data. Use #1 for ASM parsing instead. |
| 7 | F5 Networks - LTM / F5 Security / F5 Access Visibility / F5 Analytics (iApp) | App | F5 Networks & community (Archived) | Legacy LTM, ASM and APM dashboards | 2.0 / 1.0.0 | Apr – Dec 2016 | LTM · Security · Access · Analytics | ARCHIVED — 2016. F5's own Splunk apps have been unmaintained since 2016. Use #1 for data; there is no supported F5 dashboard app to replace them. |
| # | Ingestion Path | Type | Support Owner | Data Source Type Collected | Sourcetype / Config | Reference Link | Notes — Usage |
|---|---|---|---|---|---|---|---|
| 1 | BIG-IP (LTM / GTM / ASM / APM) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | BIG-IP syslog and iRule-generated events — legacy BSD format, default port 514 | sourcetypes f5:bigip:syslog, f5:bigip:irule, f5:bigip:ltm:http:irule, f5:bigip:gtm:dns:request:irule, f5:bigip:asm:syslog, f5:bigip:apm:syslog, f5:bigip:ltm:access_json → index netops (netwaf for ASM) |
SC4S docs | Pairs with #1 (app/2680). Needs vendor/product-by-source configuration, and the host must be in the syslog header. Without the f_f5_bigip filter, OS-level events fall back to nix:syslog → osnix. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for Unix and Linux | Technical Add-On | Splunk Supported | Unix/Linux OS logs, performance metrics, process/service info, package inventory, cron, hardware, network config | 10.3.4 | 1 Sep 2026 | app/833 | CURRENT STANDARD. UF-based scripted/modular inputs providing rapid operational visibility across large-scale Unix/Linux fleets; pairs with the (now-archived) Splunk App for Unix and Linux dashboards. CIM 6.x compatible. v6.0 introduced default index/.conf changes — test upgrades in non-production first. |
| 2 | Splunk Add-on for Linux | Technical Add-On | Splunk Supported | Linux performance metrics via HEC/TCP (CPU, memory, swap, disk, network, load, process, TCP connections, thermal, uptime) | 2.1.1 | 30 Mar 2026 | app/3412 | Lighter-weight, metrics-only alternative to TA #1 — pushes data via HTTP Event Collector/TCP instead of UF scripted inputs. CIM 5.x compatible. Choose based on whether you need full log collection (#1) or just metrics (#2). |
| 3 | Splunk Asset and Risk Intelligence Technical Add-on For Linux | Technical Add-On | Splunk Supported | Real-time Linux IT asset discovery & attribution (Splunk Asset and Risk Intelligence / SARI Edge Discovery) | 1.2.0 | 17 Sep 2025 | app/7416 | Feeds Splunk's Asset and Risk Intelligence product — distinct from general log ingestion in TA #1/#2; focused on asset inventory/attribution. |
| 4 | Splunk Exposure Analytics Add-on for Linux | Technical Add-On | Splunk Supported | Enriched asset & user data from Splunk forwarder endpoints (system, user, network, full-disk-encryption info) | 1.0.0 | 29 Apr 2026 | app/8692 | Optional entity-discovery source for Splunk Exposure Analytics; deploy to forwarders to enhance endpoint-derived enrichment alongside other discovery sources. |
| 5 | BeyondTrust Privilege Management for Unix and Linux | App | BeyondTrust Corporation | BeyondTrust Privilege Management — privileged command activity, recorded sessions, system-level control data | 1.0.8 | 6 Jul 2026 | app/7398 | Vendor-published example app demonstrating centralized visibility into privileged access activity on Unix/Linux; provided free as a base for custom implementations. |
| 6 | Sandfly Agentless Security for Linux | App | Sandfly Security | Sandfly agentless Linux endpoint security findings (drift detection, rootkit/intrusion checks) | 4.7.0 | 12 Feb 2026 | app/5016 | Vendor-published dashboards/inputs for Sandfly's agentless Linux security scanning product. CIM 6.x compatible. |
| 7 | OCSF TA for Linux | Technical Add-On (extension) | 3rd-party dev (Arkitech Security) | Auditd events mapped to OCSF-compliant fields (on top of TA #1's Auditd collection) | 2.3.3 | 18 Jul 2026 | app/7432 | Search-head extension adding OCSF and CIM 8.x field mapping for Auditd — ties STIG/CIS compliance data to security use cases. |
| 8 | Monitoring Linux - Metrics and Logs Forwarding | Technical Add-On | 3rd-party dev (Outcold Solutions) | Linux metrics & logs via a proprietary lightweight forwarder (alternative to UF) | 5.21.411 | 18 Nov 2024 | app/4768 | Commercial alternative collection agent for environments that prefer not to deploy a full Universal Forwarder. |
| 9 | Splunk App for Unix and Linux | App | Splunk LLC (Archived) | Consumes data ingested by TA #1 | 6.0.2 | 11 Jun 2021 | app/273 | ARCHIVED / EOL. Splunk officially end-of-sold this app 30 Apr 2021 and end-of-lifed it 13 Mar 2022, refocusing on IT Essentials Work and IT Service Intelligence (ITSI) instead — the same fate as the Windows Infrastructure companion app. |
| 10 | Splunk Add-on for Sysmon for Linux | Technical Add-On | Splunk LLC (Archived) | Sysmon for Linux events | 1.0.0 | 24 Oct 2022 | app/6652 | ARCHIVED. No confirmed modern replacement identified on Splunkbase for dedicated Sysmon-for-Linux parsing. |
| 11 | NMON Performance Monitor for Unix and Linux Systems | App | 3rd-party dev (Guilhem Marchand) | NMON performance metrics (CPU, memory, disk, network) for Unix/Linux | 1.9.21 | 30 Nov 2019 | app/1753 | ARCHIVED. Long-popular community performance app (49 reviews); evaluate TA #1/#2's native performance metrics as the modern equivalent. |
| 12 | Linux Auditd | App | 3rd-party dev (Doug Brown) | Linux Auditd security events | 3.1.0 | 18 Oct 2019 | app/2642 | ARCHIVED. Pair OCSF TA for Linux (#7) with TA #1's Auditd input for a modern equivalent. |
| 13 | Linux Secure Technology Add-On | Technical Add-On | 3rd-party dev (Doug Brown) | Linux /var/log/secure authentication & authorization events |
1.0.1 | 29 Nov 2021 | app/3476 | ARCHIVED. No confirmed modern replacement identified on Splunkbase specific to /var/log/secure parsing. |
| 14 | Linux Netfilter (iptables) Technology Add-On | Technical Add-On | 3rd-party dev (Doug Brown) | Linux Netfilter/iptables firewall logs | 1.0.0 | 2 Jul 2019 | app/3089 | ARCHIVED. Consider the SC4S "Generic *NIX" path below for appliance-style iptables/syslog forwarding, or TA #1 for host-based collection. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for Microsoft Cloud Services | Technical Add-On | Splunk Supported | Azure — Event Hubs (diagnostic, Entra ID & resource logs streamed to Event Hub), activity/audit logs, resource data, service status, Storage Table & Blob | 6.3.3 | 10 Sep 2026 | app/3110 | CURRENT STANDARD for Azure. CIM-compatible for ES, PCI and ITSI. Most inputs from the Splunk Works Azure add-on (#7) have moved here — see the migration guide. |
| 2 | Splunk Add-on for Microsoft Security | Technical Add-On | Splunk Supported | Microsoft Defender XDR (365 Defender) incidents & alerts, Defender for Endpoint alerts, Defender Advanced Hunting events | 4.0.0 | 21 Jul 2026 | app/6207 | CURRENT STANDARD for Defender. Replaces the archived Microsoft 365 Defender add-on and Defender Advanced Hunting add-on (#14, #15). Dashboards are in #5. |
| 3 | Splunk Add-on for Microsoft Office 365 | Technical Add-On | Splunk Supported | Office 365 Management Activity API — audit logs for Entra ID, SharePoint Online, Exchange Online & DLP; service status and messages; message trace | 6.1.0 | 30 Jul 2026 | app/4055 | CURRENT STANDARD for Microsoft 365. Took over message trace from the archived Reporting Web Service add-on (#16). |
| 4 | Microsoft Azure App for Splunk | App | Splunk Works (Not Supported) | Uses data from #1, #2 & #7 | 2.1.1 | 11 Dec 2024 | app/4882 | Dashboards for subscriptions, resources, VMs, metrics, storage, security monitoring and billing (beta), plus onboarding guides for app registrations. Search-head tier. |
| 5 | Microsoft 365 App for Splunk | App | Splunk Works (Not Supported) | Uses data from #2, #3 & #6 | 3.3.2 | 13 Apr 2026 | app/3786 | Dashboards for Entra ID, Defender XDR, Defender for Endpoint, Exchange, SharePoint, OneDrive, Teams and Power BI, with a step-by-step onboarding guide. Search-head tier. |
| 6 | Microsoft Teams Add-on for Splunk | Technical Add-On | Splunk Works (Not Supported) | Teams call records, sessions & segments (call quality — jitter, packet loss, RTT) via Microsoft Graph | 2.0.1 | 16 Jul 2026 | app/4994 | Feeds the Teams dashboards in #5. |
| 7 | Splunk Add on for Microsoft Azure | Technical Add-On | Splunk Works (Not Supported) | Entra ID users, sign-ins, directory audits, devices, groups & risk detections; Defender for Cloud (Security Center) alerts; Resource Graph | 4.2.0 | 15 Nov 2024 | app/3757 | LEGACY — INPUTS MIGRATED. Its own listing says the inputs have moved to Splunk-supported add-ons (mainly #1). Plan to migrate. Still includes useful alert actions (stop VM, add user to group). |
| 8 | Microsoft O365 Email Add-on for Splunk | Technical Add-On | Splunk Works (Not Supported) | M365 email from a dedicated compliance mailbox via Microsoft Graph — attachments, IOCs, SPF/DKIM/DMARC, phishing risk scoring | 2.4.18 | 24 Apr 2026 | app/5365 | Security-focused mailbox ingestion with hashing, ZIP/macro inspection and header parsing. Separate from the audit logs in #3. |
| 9 | Microsoft Cloud Service Connectors (SOAR) | SOAR Connector | Splunk Supported | Microsoft Graph, Entra ID, Defender, Azure & M365 APIs — containment & investigative playbook actions | 1.x–4.x | Sep 2025 – Sep 2026 | See notes | For Splunk SOAR (response, not parsing). Splunk publishes 15 separate Microsoft cloud connector apps, grouped here to keep the table short: MS Graph for Active Directory · Azure AD Graph · MS Graph for Office 365 · MS Graph for O365 – Federal · Microsoft 365 · Microsoft 365 Defender · Defender for Endpoint · Azure Compute · Azure SQL · Azure DevOps · Teams · OneDrive · MS Graph for SharePoint · EWS for Office 365 · Intune (SOAR Community) |
| 10 | Splunk Alerts for Microsoft Teams | App (Alert Action) | Splunk Supported | Outbound only — posts Splunk alerts to Teams channels | 1.1.11 | 27 Apr 2026 | app/4855 | Not a data source. Sends alert notifications to Teams (message cards, actions, retry through KV store). |
| 11 | Microsoft Graph Security Score Add-on | Technical Add-On | 3rd-party dev (Crossrealms) | Microsoft Secure Score via the Graph Security API | 1.3.0 | 15 Sep 2026 | app/5693 | Lightweight scripted input for tracking Secure Score over time. |
| 12 | Microsoft 365 Defender Threat Vulnerability Add-on for Splunk | Technical Add-On | 3rd-party dev (Thomas Hillesøy) | Defender Vulnerability Management (TVM) — device vulnerabilities & exposure | 2.0.2 | 17 Aug 2026 | app/6470 | CIM Vulnerabilities data model, plus reports that build ES asset lookups. Fills a gap: #2 does not collect TVM data. |
| 13 | MS Defender Advanced Hunting | Technical Add-On (search command) | 3rd-party dev (Masaki Yoshikawa) | Ad-hoc KQL Advanced Hunting queries against Defender for Endpoint, Defender XDR or Graph APIs | 0.2.6 | 8 Aug 2026 | app/6456 | Search-time custom command, not scheduled ingestion. Useful for pivoting from Splunk into Defender during investigations. |
| 14 | Microsoft Defender Advanced Hunting Add-on for Splunk | Technical Add-On | Splunk Works (Archived) | Defender Advanced Hunting events (CIM Endpoint) | 1.4.2 | 9 Jan 2026 | app/5518 | ARCHIVED — FINAL VERSION. Moved into #2. |
| 15 | Microsoft 365 Defender Add-on for Splunk | Technical Add-On | Splunk Works (Archived) | 365 Defender incidents, Defender for Endpoint alerts | 1.3.0 | 21 May 2021 | app/4959 | ARCHIVED. Data collection moved to #2 and dashboards to #5. |
| 16 | Splunk Add-on for Microsoft Office 365 Reporting Web Service | Technical Add-On | Splunk Works (Archived) | Office 365 message trace | 2.0.1 | 21 Sep 2022 | app/3720 | ARCHIVED. Moved into #3. |
| 17 | Microsoft Graph Security API Add-On / Microsoft Sentinel Add-On | Technical Add-On | Microsoft Corporation (Archived) | Graph Security API alerts (inbound) / Splunk → Sentinel log forwarding (outbound) | 1.2.6 / 1.0.6 | 7 Jun 2023 / 7 Mar 2022 | app/4564 · app/5312 | ARCHIVED. Microsoft-published add-ons that are no longer maintained. Use #2 for Defender alerts and #1 for Azure/Entra data. |
#1 current standard · #4 dashboards · #7 legacy, migrate off · #9 SOAR (Compute, SQL, DevOps)
#3 audit via Management API · #1 sign-in/audit via Event Hub · #9 SOAR (MS Graph for AD)
#3 audit & DLP · #6 Teams call quality · #8 mailbox content · #5 dashboards
#2 incidents, alerts & hunting · #12 vulnerabilities · #13 ad-hoc KQL · #11 Secure Score
| # | Ingestion Path | Type | Support Owner | Data Source Type Collected | Sourcetype / Config | Reference Link | Notes — Usage |
|---|---|---|---|---|---|---|---|
| 1 | Defender for Cloud Apps (formerly Cloud App Security / MCAS) | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | MCAS SIEM agent output as CEF — legacy BSD format, default port 514 | sourcetype cef, source microsoft:cas → index main |
SC4S docs | The only Microsoft source in SC4S. Parsed by the generic Splunk Add-on for CEF (GitHub, not Splunkbase). Check Microsoft's current SIEM-integration guidance first — the API-based add-ons above are the main path for Microsoft cloud data. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for Palo Alto Networks | Technical Add-On | Splunk Supported | Cortex XDR, IoT Security, Firewalls (NGFW), Panorama, Strata Logging Service | 4.0.0 | 14 Aug 2026 | app/7523 | CURRENT STANDARD. Official parsing TA: modular inputs for IoT Security & Cortex XDR, CIM 5.x normalisation, health-check monitoring dashboard, latest PAN-OS support. Deploy on indexers / heavy forwarders. |
| 2 | Splunk App for Palo Alto Networks | App | Splunk LLC (Supported) | Consumes data ingested by TA #1 (firewall, Panorama, XDR, IoT, SLS) | 1.0.1 | 14 Nov 2024 | app/7505 | Visualization layer: security reporting & analysis dashboards correlating app/user activity across network & security infrastructure. Search-head tier; requires TA #1. |
| 3 | Palo Alto API Inputs Add On | Technical Add-On | 3rd-party dev (Edlyn Liew) | Logs & telemetry from PAN devices via API (alternative to syslog/HEC) | 1.0.16 | 4 Dec 2025 | app/8283 | Use where syslog forwarding isn't feasible (firewalls behind NAT / restricted networks) or extra API metadata is needed; supports custom API endpoint scripts. |
| 4 | CCX Palo Alto Cortex XDR (CEF) | Technical Add-On | 3rd party — CyberCX | Cortex XDR syslog (CEF) forwarded from Cortex Data Lake via syslog server | 1.0.2 | 29 Aug 2025 | app/6326 | Field-extraction bundle mapping XDR CEF logs to CIM datamodels: Network Traffic, Change, Malware, Alerts, IDS. Not Splunk supported. |
| 5 | Palo Alto Cortex XDR | SOAR Connector | SOAR Community | Cortex XDR API — incidents, endpoints | 1.2.1 | 28 Apr 2025 | app/6046 | For Splunk SOAR (response, not parsing): on-poll ingest, list endpoints, block/allow hash, quarantine / unquarantine device, get incident details. |
| 6 | Prisma Cloud Audit Input | Technical Add-On (input) | 3rd-party dev (Brett Adams) | Prisma Cloud audit logs (API pull) | 1.0.4 | 3 Aug 2026 | app/6379 | Pulls the Prisma Cloud audit trail into Splunk for admin / compliance visibility. |
| 7 | Add-on for Prisma Cloud Audit | Technical Add-On (input) | 3rd-party dev (Rotimi Akinbobola) | Audit events from Prisma Cloud | 2.0.1 | 20 Sep 2026 | app/7700 | Alternative Prisma Cloud audit fetcher — compare features against #6 before selecting. |
| 8 | Palo Alto Networks Add-on for Splunk (Splunk_TA_paloalto) | Technical Add-On | Palo Alto Networks | NGFW, Panorama, Traps ESM; also Aperture / SaaS Security, Cortex XDR, MineMeld / AutoFocus | 8.1.3 | 24 May 2024 | app/2757 | DEPRECATED / ARCHIVED. Legacy PAN-owned TA. Migrate to #1 (Splunk-supported); note revised CIM mapping, macros, and input config changes during migration. |
| 9 | Palo Alto Networks App for Splunk (SplunkforPaloAltoNetworks) | App | Palo Alto Networks | Consumes legacy TA #8 data (firewall, GlobalProtect, WildFire, Traps, Aperture) | 8.1.3 | 24 May 2024 | app/491 | DEPRECATED / ARCHIVED. Legacy dashboards: adversary attacks, incidents, SaaS usage, system health, config audit, malware, GlobalProtect VPN. Migrate to #2. |
| 10 | CCX Add-on for Palo Alto Networks (PAN IOT) | Technical Add-On | 3rd party — CyberCX | IoT Security API — alert events, detections, vulnerabilities | 1.0.0 | 27 Feb 2024 | app/7250 | ARCHIVED. CIM-compliant extractions (Alert, Endpoint, Network Traffic, IDS, Vulnerabilities). Superseded by the native IoT input in TA #1. |
#1 current standard · #8 / #9 legacy, migrate off · #3 API-based alternative
#1 native SLS input · #4 CEF-via-syslog extraction
#1 API modular input · #4 CEF syslog parsing · #5 SOAR response actions
#1 native input · #10 archived CyberCX alternative
#6 / #7 audit logs. Prisma Cloud Compute (Twistlock) App — app/4555 by Palo Alto Networks — covers incidents & forensics via the Compute API (verify latest version on the listing).
| # | Ingestion Path | Type | Support Owner | Data Source Type Collected | Sourcetype / Config | Reference Link | Notes — Usage |
|---|---|---|---|---|---|---|---|
| 1 | PAN-OS (NGFW / Panorama / Cortex Data Lake) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | NGFW/Panorama/CDL syslog — legacy BSD default port 514, or IETF Framed on port 601 | sourcetypes pan:log, pan:globalprotect, pan:traffic, pan:threat, pan:system, pan:config, pan:hipmatch, pan:correlation, pan:userid |
SC4S docs | Alternative transport/routing layer to the direct syslog input already built into #1 (app/7523); still requires that TA on search heads for CIM parsing/dashboards. Useful if you already run SC4S for centralized syslog routing across many vendors. |
| 2 | Cortex XDR | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Cortex XDR / Cortex Data Lake syslog — requires TLS, IETF Framed, port 5425 | sourcetypes pan:*, pan:xsoar |
SC4S docs | SC4S docs still reference the deprecated #8 (app/2757) — pair with current-standard #1 (app/7523) instead for parsing. |
| 3 | Traps | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Traps ESM syslog — legacy BSD format, default port 514 | sourcetype pan:traps4 |
SC4S docs | Pairs with #1 (app/7523) for parsing. |
| 4 | Prisma SD-WAN ION | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Prisma SD-WAN ION flow, authentication & event syslogs (MSG format) | sourcetypes prisma:sd-wan:flow, prisma:sd-wan:authentication, prisma:sd-wan:event |
SC4S docs | No Splunkbase Add-on required. Distinct data source from Prisma Cloud (#6/#7, API-based audit logs) — Prisma SD-WAN ION is a separate networking product ingested purely via syslog. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for Salesforce | Technical Add-On | Splunk Supported | Salesforce REST API — Event Log File data & SOQL object query output | 7.0.1 | 3 Sep 2026 | app/3549 | CURRENT STANDARD. CIM-compatible inputs for use with Enterprise Security, PCI Compliance app, ITSI. v2.0.0 introduced breaking changes — always test upgrades in non-production before deploying. |
| 2 | Salesforce | SOAR Connector | Splunk Supported | Salesforce object management API | 3.0.1 | 21 Jul 2026 | app/5930 | For Splunk SOAR (response, not parsing): create/update/manage Salesforce objects as part of automated playbooks. FIPS compliant. |
| 3 | Splunk Add-on for Salesforce Streaming API | Technical Add-On | Splunk Works (Not Supported) | Salesforce Streaming API — PushTopic, generic, platform & Change Data Capture (CDC) events | 2.1.0 | 24 Jul 2026 | app/5689 | Near real-time push-based ingestion, complementary to #1's polled REST API collection. Not officially Splunk supported despite Splunk Works authorship. |
| 4 | CCX Extensions for Salesforce | Technical Add-On (extension) | 3rd party — CyberCX | Enriches sourcetypes already ingested by #1 / #3 (login history, setup audit trail, log file, streaming login/report/security events) | 1.0.6 | 24 Aug 2025 | app/7174 | Search-head-only extension adding field extraction & CIM compliance (Alerts, Authentication, Change, Data Access, IDS) on top of #1 and #3 — does not replace either add-on. |
| 5 | Salesforce Commerce Cloud Connector for CX Monitoring | App | 3rd-party dev (AIOPS Group Monitoring Team) | Salesforce Commerce Cloud (SFCC) — logs, orders, products, pricebooks, inventory, eCDN, customer data | 6.15.0 | 21 Sep 2026 | app/6570 | Broader CX-monitoring solution (not Salesforce CRM-specific): 360° monitoring with self-healing, 110+ real-time alerts, 200+ KPIs across the SFCC storefront stack. |
| 6 | Salesforce Monitoring App for Splunk | App | 3rd-party dev (Rojo Consultancy BV) | Salesforce transactional & operational data (login history, platform/object stats, REST API usage) | 1.0.0 | 24 Sep 2024 | app/6579 | NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date — listing shows "This app has no available versions." Out-of-the-box dashboards for login trends, org limits, and API insights once available. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for Microsoft Windows | Technical Add-On | Splunk Supported | Windows Event Logs (Security/System/Application/etc.), performance counters, WMI, registry, Active Directory, DNS, DHCP, file system changes | 11.0.2 | 17 Aug 2026 | app/742 | CURRENT STANDARD. Since v6.0.0 this TA has absorbed the standalone Splunk Add-on for Windows DNS and Splunk Add-on for Microsoft Active Directory — do not run those alongside v6.0.0+. CIM 5.x compatible. v5.0.0 introduced breaking changes — test upgrades in non-production first. |
| 2 | Splunk Asset and Risk Intelligence Technical Add-on For Windows | Technical Add-On | Splunk Supported | Real-time Windows IT asset discovery & attribution (Splunk Asset and Risk Intelligence / SARI Edge Discovery) | 1.2.0 | 17 Sep 2025 | app/7214 | Feeds Splunk's Asset and Risk Intelligence product — distinct from general log ingestion in TA #1; focused on asset inventory/attribution. |
| 3 | Windows Remote Management | SOAR Connector | Splunk Supported | Windows Remote Management (WinRM) — remote command & script execution | 3.0.1 | 21 Sep 2026 | app/5875 | For Splunk SOAR (response, not parsing): run commands/scripts on remote Windows hosts via WinRM as part of automated playbooks. |
| 4 | TA-winfw Technology Addon for Windows Firewall | Technical Add-On | 3rd-party dev (Andreas Roth) | Windows Firewall event logs | 1.0.1 | 21 Aug 2024 | app/3300 | ARCHIVED on Splunkbase (detected 23 Sep 2026). Dedicated parsing for Windows Firewall with Advanced Security logs, complementary to TA #1's general Windows Event Log coverage. |
| 5 | CCX Microsoft Windows Extensions (Defender for Endpoint and Sysmon) | Technical Add-On (extension) | 3rd party — CyberCX | Enriches sourcetypes already ingested by TA #1 (Microsoft Defender for Endpoint & Sysmon events) | 1.0.8 | 25 Sep 2025 | app/6313 | Search-head-only extension adding field extraction & CIM compliance on top of TA #1 — does not replace it. |
| 6 | Microsoft Windows Firewall Observability | Technical Add-On | 3rd-party dev (Amara Mohamed Traore) | Windows host firewall traffic & configuration-change activity | 4.0.0 | 25 Aug 2026 | app/7790 | CIM 6.x compliant; collects, parses and visualizes workstation/server firewall traffic and config changes with dedicated dashboards. |
| 7 | Windows Certificate Store Add-on for Splunk | Technical Add-On | 3rd-party dev (Crossrealms) | Windows certificate store contents/metadata | 1.0.2 | 22 Sep 2025 | app/7013 | Inventories certificates on Windows hosts for expiry tracking and compliance visibility. |
| 8 | Windows Security Operations Center | App | 3rd-party dev (Bojan Zdrnja) | Consumes data ingested by TA #1 | 2.0.1 | 19 Sep 2025 | app/647 | Long-running community SOC dashboard app on top of TA #1 — correlation views for endpoint/security-relevant Windows events. |
| 9 | Add-On for Windows DNS Analytical Logging | Technical Add-On | 3rd-party dev (Hugh Kelley) | Windows DNS Server analytical/diagnostic event logs | — | 9 Jul 2023 | app/4300 | NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date. Last updated 2023 — evaluate TA #1's built-in DNS input first. |
| 10 | Windows Lateral Movement Detection | Technical Add-On | 3rd-party dev (community) | Windows-based forensic inputs for lateral-movement threat hunting (built on SANS' 2018 "Hunt Evil" poster) | — | 17 Sep 2025 | app/4581 | NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date — listing shows "This app has no available versions." |
| 11 | Splunk App for Windows Infrastructure | App | Splunk LLC (Archived) | Consumed data from the legacy Windows TAs (superseded) | 2.0.4 | 30 Aug 2021 | app/1680 | ARCHIVED / EOL. Splunk officially end-of-sold this app 31 Jul 2021 and end-of-lifed it 21 Oct 2021, refocusing on IT Essentials Work and IT Service Intelligence (ITSI) instead. |
| 12 | Splunk Add-on for Microsoft Windows DNS | Technical Add-On | Splunk LLC (Archived) | Windows DNS Server logs | 1.0.1 | 11 Oct 2016 | app/3208 | DEPRECATED / ARCHIVED. Fully absorbed into TA #1 as of v6.0.0 — do not install alongside TA #1 v6.0.0+. |
| 13 | TA for Microsoft Windows Defender | Technical Add-On | 3rd-party dev (Patrick O'Connell) | Windows Defender antivirus/antimalware events | 1.0.8 | 9 Dec 2021 | app/3734 | ARCHIVED. Consider CCX Microsoft Windows Extensions (#5) or TA #1's native Defender coverage instead. |
| 14 | Microsoft Windows DHCP addon for Splunk | Technical Add-On | 3rd-party dev (Nick Hills) | Windows DHCP Server logs | 1.2.0 | 17 Feb 2020 | app/4359 | ARCHIVED. No modern replacement identified on Splunkbase; evaluate custom inputs or generic file monitoring for DHCP server logs. |
| 15 | Splunk 5.x App for Microsoft Windows | App | Splunk Works (Archived) | Legacy Windows infrastructure dashboards | 5.0.2 | 12 Oct 2013 | app/272 | ARCHIVED — very old (2013). Long superseded by #11 and now by TA #1 + #8. Kept for historical reference only. |