Splunkbase App Watcher

Apps and Technical Add-Ons available on Splunkbase, organised by vendor — click a tab below to jump to a vendor's list.

Designed and Built by See Tah Wee
Not an official Splunk or Cisco page
Verified against live Splunkbase listings · Compiled 14 Aug 2026
Palo Alto Networks 10 Splunkbase apps · 4 SC4S sources
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for Palo Alto Networks Technical Add-On Splunk Supported Cortex XDR, IoT Security, Firewalls (NGFW), Panorama, Strata Logging Service 3.1.0 22 May 2026 app/7523 CURRENT STANDARD. Official parsing TA: modular inputs for IoT Security & Cortex XDR, CIM 5.x normalisation, health-check monitoring dashboard, latest PAN-OS support. Deploy on indexers / heavy forwarders.
2 Splunk App for Palo Alto Networks App Splunk LLC (Supported) Consumes data ingested by TA #1 (firewall, Panorama, XDR, IoT, SLS) 1.0.1 14 Nov 2024 app/7505 Visualization layer: security reporting & analysis dashboards correlating app/user activity across network & security infrastructure. Search-head tier; requires TA #1.
3 Palo Alto API Inputs Add On Technical Add-On 3rd-party dev (Edlyn Liew) Logs & telemetry from PAN devices via API (alternative to syslog/HEC) 1.0.16 4 Dec 2025 app/8283 Use where syslog forwarding isn't feasible (firewalls behind NAT / restricted networks) or extra API metadata is needed; supports custom API endpoint scripts.
4 CCX Palo Alto Cortex XDR (CEF) Technical Add-On 3rd party — CyberCX Cortex XDR syslog (CEF) forwarded from Cortex Data Lake via syslog server 1.0.2 29 Aug 2025 app/6326 Field-extraction bundle mapping XDR CEF logs to CIM datamodels: Network Traffic, Change, Malware, Alerts, IDS. Not Splunk supported.
5 Palo Alto Cortex XDR SOAR Connector SOAR Community Cortex XDR API — incidents, endpoints 1.2.1 28 Apr 2025 app/6046 For Splunk SOAR (response, not parsing): on-poll ingest, list endpoints, block/allow hash, quarantine / unquarantine device, get incident details.
6 Prisma Cloud Audit Input Technical Add-On (input) 3rd-party dev (Brett Adams) Prisma Cloud audit logs (API pull) 1.0.2 10 Aug 2025 app/6379 Pulls the Prisma Cloud audit trail into Splunk for admin / compliance visibility.
7 Add-on for Prisma Cloud Audit Technical Add-On (input) 3rd-party dev (Rotimi Akinbobola) Audit events from Prisma Cloud 1.0.1 21 Apr 2025 app/7700 Alternative Prisma Cloud audit fetcher — compare features against #6 before selecting.
8 Palo Alto Networks Add-on for Splunk (Splunk_TA_paloalto) Technical Add-On Palo Alto Networks NGFW, Panorama, Traps ESM; also Aperture / SaaS Security, Cortex XDR, MineMeld / AutoFocus 8.1.3 24 May 2024 app/2757 DEPRECATED / ARCHIVED. Legacy PAN-owned TA. Migrate to #1 (Splunk-supported); note revised CIM mapping, macros, and input config changes during migration.
9 Palo Alto Networks App for Splunk (SplunkforPaloAltoNetworks) App Palo Alto Networks Consumes legacy TA #8 data (firewall, GlobalProtect, WildFire, Traps, Aperture) 8.1.3 24 May 2024 app/491 DEPRECATED / ARCHIVED. Legacy dashboards: adversary attacks, incidents, SaaS usage, system health, config audit, malware, GlobalProtect VPN. Migrate to #2.
10 CCX Add-on for Palo Alto Networks (PAN IOT) Technical Add-On 3rd party — CyberCX IoT Security API — alert events, detections, vulnerabilities 1.0.0 27 Feb 2024 app/7250 ARCHIVED. CIM-compliant extractions (Alert, Endpoint, Network Traffic, IDS, Vulnerabilities). Superseded by the native IoT input in TA #1.

Palo Alto Networks — Categorised by Data Source

NGFW / Panorama (Syslog)

#1 current standard · #8 / #9 legacy, migrate off · #3 API-based alternative

Strata Logging Service / Cortex Data Lake

#1 native SLS input · #4 CEF-via-syslog extraction

Cortex XDR

#1 API modular input · #4 CEF syslog parsing · #5 SOAR response actions

IoT Security

#1 native input · #10 archived CyberCX alternative

Prisma Cloud

#6 / #7 audit logs. Prisma Cloud Compute (Twistlock) App — app/4555 by Palo Alto Networks — covers incidents & forensics via the Compute API (verify latest version on the listing).

Key notes: the Palo Alto App + Add-on pair (#1 + #2) is now officially Splunk Supported — all updates and support are managed by Splunk. Legacy #8 / #9 are deprecated; #10 is archived — all three are listed last in the table below. Splunkbase Classic will be deactivated on 18 Feb 2026 — update any bookmarked classic links.

Palo Alto Networks — Additional GDI Option: Splunk Connect for Syslog (SC4S)

Palo Alto Networks is a recognised vendor in Splunk Connect for Syslog (SC4S), a community syslog-routing layer that's an alternative (or complement) to HEC/modular-input based GDI. SC4S auto-assigns sourcetypes and routes events to an index — it still needs a parsing TA installed on the search head for CIM/dashboards unless noted otherwise.
# Ingestion Path Type Support Owner Data Source Type Collected Sourcetype / Config Reference Link Notes — Usage
1 PAN-OS (NGFW / Panorama / Cortex Data Lake) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) NGFW/Panorama/CDL syslog — legacy BSD default port 514, or IETF Framed on port 601 sourcetypes pan:log, pan:globalprotect, pan:traffic, pan:threat, pan:system, pan:config, pan:hipmatch, pan:correlation, pan:userid SC4S docs Alternative transport/routing layer to the direct syslog input already built into #1 (app/7523); still requires that TA on search heads for CIM parsing/dashboards. Useful if you already run SC4S for centralized syslog routing across many vendors.
2 Cortex XDR SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Cortex XDR / Cortex Data Lake syslog — requires TLS, IETF Framed, port 5425 sourcetypes pan:*, pan:xsoar SC4S docs SC4S docs still reference the deprecated #8 (app/2757) — pair with current-standard #1 (app/7523) instead for parsing.
3 Traps SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Traps ESM syslog — legacy BSD format, default port 514 sourcetype pan:traps4 SC4S docs Pairs with #1 (app/7523) for parsing.
4 Prisma SD-WAN ION SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Prisma SD-WAN ION flow, authentication & event syslogs (MSG format) sourcetypes prisma:sd-wan:flow, prisma:sd-wan:authentication, prisma:sd-wan:event SC4S docs No Splunkbase Add-on required. Distinct data source from Prisma Cloud (#6/#7, API-based audit logs) — Prisma SD-WAN ION is a separate networking product ingested purely via syslog.
Check Point 4 Splunkbase apps · 3 SC4S sources
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Check Point Firewall SOAR Connector Splunk Supported Check Point Firewall management API — endpoint & network containment actions 4.0.0 4 Aug 2026 app/5777 For Splunk SOAR (response, not parsing): block/unblock IP, add/remove host from group, and other containment playbook actions against Check Point firewalls. FIPS compliant.
2 Check Point App for Splunk Technical Add-On Check Point (Not Supported) Firewall, endpoint, mobile & cloud logs via Check Point Log Exporter (all Check Point technologies/platforms) 1.1.6 6 Jul 2026 app/4293 CURRENT STANDARD. Primary parsing TA: CIM-compatible, integrates with Enterprise Security & SmartEvent dashboards (General Overview, Threat Prevention, Cyber Attack View), MITRE ATT&CK analytics for SandBlast malware findings. Uses Log Exporter (syslog) — see Check Point sk122323.
3 Check Point Exposure Management (Cyberint) Technical Add-On 3rd-party dev (bensa bensa) Cyberint / Argos Edge threat intelligence — alerts, attack tools, phishing & fraud detections 1.2.0 4 Aug 2026 app/7117 Fetches enriched, intelligence-driven threat data with automatic incident-status sync; ships pre-built dashboards for investigation.
4 Splunk Add-on for Check Point Log Exporter Technical Add-On Splunk LLC (Archived) Check Point Log Exporter over syslog (RFC5424) 1.2.0 15 Feb 2024 app/5478 ARCHIVED. Splunk-built TA specifically for Log Exporter syslog ingestion (sourcetype cp_log:syslog); Splunkbase lists it as an archived add-on. Use #2 (app/4293) for parsing instead — see the SC4S GDI option below for the Log Exporter transport layer.

Check Point — Additional GDI Option: Splunk Connect for Syslog (SC4S)

Check Point is a recognised vendor in Splunk Connect for Syslog (SC4S), a community syslog-routing layer that's an alternative (or complement) to HEC/modular-input based GDI. SC4S auto-assigns sourcetypes and routes events to an index — it still needs a parsing TA installed on the search head for CIM/dashboards unless noted otherwise.
# Ingestion Path Type Support Owner Data Source Type Collected Sourcetype / Config Reference Link Notes — Usage
1 Firewall OS (direct syslog) SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Native/raw firewall syslog output (no Log Exporter involved) sourcetype cp_log:fw:syslog → index netops SC4S docs No Splunkbase Add-on required — for devices sending direct syslog without Check Point's Log Exporter.
2 Log Exporter (Syslog / RFC5424) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Log Exporter output over IETF RFC5424 syslog, port 514/TCP sourcetype cp_log:syslog → index netops SC4S docs SC4S references the now-ARCHIVED #4 (app/5478); pair with #2 (app/4293) for parsing instead. SC4S notes Check Point's own Log Exporter config template was defective as of 2/1/2022 — use SC4S's corrected config.
3 Log Exporter (Splunk legacy format) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Legacy "Splunk format" Log Exporter output (non-RFC3164 conformant) sourcetype cp_log SC4S docs LEGACY — avoid for new deployments. SC4S docs explicitly recommend Log Exporter (Syslog) above instead. Pairs with #2 (app/4293).
Salesforce 6 apps
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for Salesforce Technical Add-On Splunk Supported Salesforce REST API — Event Log File data & SOQL object query output 7.0.0 31 Jul 2026 app/3549 CURRENT STANDARD. CIM-compatible inputs for use with Enterprise Security, PCI Compliance app, ITSI. v2.0.0 introduced breaking changes — always test upgrades in non-production before deploying.
2 Salesforce SOAR Connector Splunk Supported Salesforce object management API 3.0.1 21 Jul 2026 app/5930 For Splunk SOAR (response, not parsing): create/update/manage Salesforce objects as part of automated playbooks. FIPS compliant.
3 Splunk Add-on for Salesforce Streaming API Technical Add-On Splunk Works (Not Supported) Salesforce Streaming API — PushTopic, generic, platform & Change Data Capture (CDC) events 2.1.0 24 Jul 2026 app/5689 Near real-time push-based ingestion, complementary to #1's polled REST API collection. Not officially Splunk supported despite Splunk Works authorship.
4 CCX Extensions for Salesforce Technical Add-On (extension) 3rd party — CyberCX Enriches sourcetypes already ingested by #1 / #3 (login history, setup audit trail, log file, streaming login/report/security events) 1.0.6 24 Aug 2025 app/7174 Search-head-only extension adding field extraction & CIM compliance (Alerts, Authentication, Change, Data Access, IDS) on top of #1 and #3 — does not replace either add-on.
5 Salesforce Commerce Cloud Connector for CX Monitoring App 3rd-party dev (AIOPS Group Monitoring Team) Salesforce Commerce Cloud (SFCC) — logs, orders, products, pricebooks, inventory, eCDN, customer data 6.10.0 21 May 2026 app/6570 Broader CX-monitoring solution (not Salesforce CRM-specific): 360° monitoring with self-healing, 110+ real-time alerts, 200+ KPIs across the SFCC storefront stack.
6 Salesforce Monitoring App for Splunk App 3rd-party dev (Rojo Consultancy BV) Salesforce transactional & operational data (login history, platform/object stats, REST API usage) 1.0.0 24 Sep 2024 app/6579 NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date — listing shows "This app has no available versions." Out-of-the-box dashboards for login trends, org limits, and API insights once available.
Note: Salesforce is not a recognised vendor in Splunk Connect for Syslog (SC4S) — its data sources (REST/Streaming APIs) are not syslog-based, so SC4S provides no alternative GDI path here. All ingestion options above use API/HEC-based inputs instead.
Alcatel 0 Splunkbase apps · 1 SC4S source
No dedicated Splunkbase app or Technical Add-On exists for Alcatel — confirmed via a live Splunkbase search. However, Alcatel switches are a recognised source in Splunk Connect for Syslog (SC4S), which routes their logs directly without needing an installed app.
# Ingestion Path Type Support Owner Data Source Type Collected Sourcetype / Config Reference Link Notes — Usage
1 Alcatel Switch (via Splunk Connect for Syslog) SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Alcatel switch syslogs — legacy BSD format, default port 514, MSG-format based filter sourcetype alcatel:switch → index netops SC4S docs No Splunkbase Add-on required — SC4S's built-in filter recognises Alcatel switch syslog and assigns alcatel:switch automatically. If a dedicated parsing TA is ever published on Splunkbase, add it here as a normal row.