Splunkbase App Watcher

Apps and Technical Add-Ons available on Splunkbase, organised by vendor — click a tab below to jump to a vendor's list.

Designed and Built by See Tah Wee
Not an official Splunk or Cisco page
Verified against live Splunkbase listings · Compiled 14 Aug 2026
Alcatel 0 Splunkbase apps · 1 SC4S source
No dedicated Splunkbase app or Technical Add-On exists for Alcatel — confirmed via a live Splunkbase search. However, Alcatel switches are a recognised source in Splunk Connect for Syslog (SC4S), which routes their logs directly without needing an installed app.
# Ingestion Path Type Support Owner Data Source Type Collected Sourcetype / Config Reference Link Notes — Usage
1 Alcatel Switch (via Splunk Connect for Syslog) SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Alcatel switch syslogs — legacy BSD format, default port 514, MSG-format based filter sourcetype alcatel:switch → index netops SC4S docs No Splunkbase Add-on required — SC4S's built-in filter recognises Alcatel switch syslog and assigns alcatel:switch automatically. If a dedicated parsing TA is ever published on Splunkbase, add it here as a normal row.
AWS 7 apps
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for Amazon Web Services (AWS) Technical Add-On Splunk Supported AWS Config, EC2/EBS metadata, Inspector, CloudTrail, CloudWatch (logs/metrics/billing), S3/CloudFront/ELB access logs, generic S3/Kinesis/SQS, Amazon Security Lake 8.2.1 30 Jul 2026 app/1876 CURRENT STANDARD. Modular-input TA, CIM 5.x compatible. From v7.0.0 it has absorbed the Splunk Add-on for Amazon Security Lake (uninstall that add-on before upgrading to avoid duplication). Splunk Cloud users should also evaluate the newer Splunk Data Inputs (formerly Data Manager) onboarding flow, which co-exists with this TA.
2 Splunk App for AWS Security Dashboards App Splunk Supported Consumes data ingested by TA #1 1.3.0 7 Feb 2026 app/6311 Visualization layer: pre-built security dashboards on top of TA #1. Search-head tier; requires TA #1.
3 Splunk Add-on for AWS Security Hub Technical Add-On Splunk Supported AWS Security Hub — real-time findings 1.1.1 app/8642 PREMIUM. Requires a subscription via "AWS Security Hub Extended." Converts real-time Security Hub events into findings/intermediate findings for Splunk Enterprise Security — separate from the general-purpose TA #1.
4 AWS Service Connectors (SOAR) SOAR Connector Splunk Supported AWS service management APIs — containment & investigative playbook actions 2.x Jul–Aug 2026 See notes For Splunk SOAR (response, not parsing). Splunk publishes this as 13 separate per-service connector apps, consolidated here for brevity: EC2 · GuardDuty · S3 · CloudTrail · IAM · Security Token Service · Athena · Systems Manager · Security Hub · Lambda · WAF V2 · Inspector · DynamoDB
5 CCX Add-on for AWS Products Technical Add-On (extension) 3rd party — CyberCX Enriches sourcetypes already ingested by TA #1 (Network Firewall, WAF, S3 VPC Flow, Macie, API Gateway Access Logs, Security Hub Custom) 1.2.9 4 Aug 2026 app/6542 Search-head-only extension adding field extraction & CIM compliance (Alert, Change, Network Traffic, Web) on top of TA #1 — does not replace it. Ingest via SQS-based S3 custom data type or syslog.
6 AWS Web Application Firewall Add-on Technical Add-On 3rd-party dev (Hurricane Labs) AWS WAF logs via Kinesis Firehose (JSON) 1.0.6 16 Dec 2025 app/4714 CIM 4.0+ compliant, Enterprise Security-ready. Includes a guide for routing AWS WAF logs to Splunk via Kinesis Firehose.
7 AWS Trusted Advisor Aggregator App 3rd-party dev (community, built on Hurricane Labs foundations) AWS Trusted Advisor recommendations across one or more accounts (cost, performance, security) 1.2.1 27 Dec 2024 app/4207 Pre-built multi-account dashboard; supports AWS Access/Secret keys, instance-profile credentials, or AssumeRole for cross-account data collection.
Note: AWS is not a recognised vendor in Splunk Connect for Syslog (SC4S) — verified against the SC4S "Known Vendors" list. AWS data sources are API/HEC-based (CloudTrail, CloudWatch, Kinesis, S3, etc.), not syslog, so SC4S provides no alternative GDI path here. Filtered out of the 25 raw Splunkbase search results: ITSI-specific content packs, a standalone DFD visualizer tool, and several low-adoption/duplicate community add-ons (0 reviews, overlapping scope with #6).
Check Point 4 Splunkbase apps · 3 SC4S sources
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Check Point Firewall SOAR Connector Splunk Supported Check Point Firewall management API — endpoint & network containment actions 4.0.0 4 Aug 2026 app/5777 For Splunk SOAR (response, not parsing): block/unblock IP, add/remove host from group, and other containment playbook actions against Check Point firewalls. FIPS compliant.
2 Check Point App for Splunk Technical Add-On Check Point (Not Supported) Firewall, endpoint, mobile & cloud logs via Check Point Log Exporter (all Check Point technologies/platforms) 1.1.6 6 Jul 2026 app/4293 CURRENT STANDARD. Primary parsing TA: CIM-compatible, integrates with Enterprise Security & SmartEvent dashboards (General Overview, Threat Prevention, Cyber Attack View), MITRE ATT&CK analytics for SandBlast malware findings. Uses Log Exporter (syslog) — see Check Point sk122323.
3 Check Point Exposure Management (Cyberint) Technical Add-On 3rd-party dev (bensa bensa) Cyberint / Argos Edge threat intelligence — alerts, attack tools, phishing & fraud detections 1.2.0 4 Aug 2026 app/7117 Fetches enriched, intelligence-driven threat data with automatic incident-status sync; ships pre-built dashboards for investigation.
4 Splunk Add-on for Check Point Log Exporter Technical Add-On Splunk LLC (Archived) Check Point Log Exporter over syslog (RFC5424) 1.2.0 15 Feb 2024 app/5478 ARCHIVED. Splunk-built TA specifically for Log Exporter syslog ingestion (sourcetype cp_log:syslog); Splunkbase lists it as an archived add-on. Use #2 (app/4293) for parsing instead — see the SC4S GDI option below for the Log Exporter transport layer.

Check Point — Additional GDI Option: Splunk Connect for Syslog (SC4S)

Check Point is a recognised vendor in Splunk Connect for Syslog (SC4S), a community syslog-routing layer that's an alternative (or complement) to HEC/modular-input based GDI. SC4S auto-assigns sourcetypes and routes events to an index — it still needs a parsing TA installed on the search head for CIM/dashboards unless noted otherwise.
# Ingestion Path Type Support Owner Data Source Type Collected Sourcetype / Config Reference Link Notes — Usage
1 Firewall OS (direct syslog) SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Native/raw firewall syslog output (no Log Exporter involved) sourcetype cp_log:fw:syslog → index netops SC4S docs No Splunkbase Add-on required — for devices sending direct syslog without Check Point's Log Exporter.
2 Log Exporter (Syslog / RFC5424) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Log Exporter output over IETF RFC5424 syslog, port 514/TCP sourcetype cp_log:syslog → index netops SC4S docs SC4S references the now-ARCHIVED #4 (app/5478); pair with #2 (app/4293) for parsing instead. SC4S notes Check Point's own Log Exporter config template was defective as of 2/1/2022 — use SC4S's corrected config.
3 Log Exporter (Splunk legacy format) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Legacy "Splunk format" Log Exporter output (non-RFC3164 conformant) sourcetype cp_log SC4S docs LEGACY — avoid for new deployments. SC4S docs explicitly recommend Log Exporter (Syslog) above instead. Pairs with #2 (app/4293).
Palo Alto Networks 10 Splunkbase apps · 4 SC4S sources
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for Palo Alto Networks Technical Add-On Splunk Supported Cortex XDR, IoT Security, Firewalls (NGFW), Panorama, Strata Logging Service 3.1.0 22 May 2026 app/7523 CURRENT STANDARD. Official parsing TA: modular inputs for IoT Security & Cortex XDR, CIM 5.x normalisation, health-check monitoring dashboard, latest PAN-OS support. Deploy on indexers / heavy forwarders.
2 Splunk App for Palo Alto Networks App Splunk LLC (Supported) Consumes data ingested by TA #1 (firewall, Panorama, XDR, IoT, SLS) 1.0.1 14 Nov 2024 app/7505 Visualization layer: security reporting & analysis dashboards correlating app/user activity across network & security infrastructure. Search-head tier; requires TA #1.
3 Palo Alto API Inputs Add On Technical Add-On 3rd-party dev (Edlyn Liew) Logs & telemetry from PAN devices via API (alternative to syslog/HEC) 1.0.16 4 Dec 2025 app/8283 Use where syslog forwarding isn't feasible (firewalls behind NAT / restricted networks) or extra API metadata is needed; supports custom API endpoint scripts.
4 CCX Palo Alto Cortex XDR (CEF) Technical Add-On 3rd party — CyberCX Cortex XDR syslog (CEF) forwarded from Cortex Data Lake via syslog server 1.0.2 29 Aug 2025 app/6326 Field-extraction bundle mapping XDR CEF logs to CIM datamodels: Network Traffic, Change, Malware, Alerts, IDS. Not Splunk supported.
5 Palo Alto Cortex XDR SOAR Connector SOAR Community Cortex XDR API — incidents, endpoints 1.2.1 28 Apr 2025 app/6046 For Splunk SOAR (response, not parsing): on-poll ingest, list endpoints, block/allow hash, quarantine / unquarantine device, get incident details.
6 Prisma Cloud Audit Input Technical Add-On (input) 3rd-party dev (Brett Adams) Prisma Cloud audit logs (API pull) 1.0.2 10 Aug 2025 app/6379 Pulls the Prisma Cloud audit trail into Splunk for admin / compliance visibility.
7 Add-on for Prisma Cloud Audit Technical Add-On (input) 3rd-party dev (Rotimi Akinbobola) Audit events from Prisma Cloud 1.0.1 21 Apr 2025 app/7700 Alternative Prisma Cloud audit fetcher — compare features against #6 before selecting.
8 Palo Alto Networks Add-on for Splunk (Splunk_TA_paloalto) Technical Add-On Palo Alto Networks NGFW, Panorama, Traps ESM; also Aperture / SaaS Security, Cortex XDR, MineMeld / AutoFocus 8.1.3 24 May 2024 app/2757 DEPRECATED / ARCHIVED. Legacy PAN-owned TA. Migrate to #1 (Splunk-supported); note revised CIM mapping, macros, and input config changes during migration.
9 Palo Alto Networks App for Splunk (SplunkforPaloAltoNetworks) App Palo Alto Networks Consumes legacy TA #8 data (firewall, GlobalProtect, WildFire, Traps, Aperture) 8.1.3 24 May 2024 app/491 DEPRECATED / ARCHIVED. Legacy dashboards: adversary attacks, incidents, SaaS usage, system health, config audit, malware, GlobalProtect VPN. Migrate to #2.
10 CCX Add-on for Palo Alto Networks (PAN IOT) Technical Add-On 3rd party — CyberCX IoT Security API — alert events, detections, vulnerabilities 1.0.0 27 Feb 2024 app/7250 ARCHIVED. CIM-compliant extractions (Alert, Endpoint, Network Traffic, IDS, Vulnerabilities). Superseded by the native IoT input in TA #1.

Palo Alto Networks — Categorised by Data Source

NGFW / Panorama (Syslog)

#1 current standard · #8 / #9 legacy, migrate off · #3 API-based alternative

Strata Logging Service / Cortex Data Lake

#1 native SLS input · #4 CEF-via-syslog extraction

Cortex XDR

#1 API modular input · #4 CEF syslog parsing · #5 SOAR response actions

IoT Security

#1 native input · #10 archived CyberCX alternative

Prisma Cloud

#6 / #7 audit logs. Prisma Cloud Compute (Twistlock) App — app/4555 by Palo Alto Networks — covers incidents & forensics via the Compute API (verify latest version on the listing).

Key notes: the Palo Alto App + Add-on pair (#1 + #2) is now officially Splunk Supported — all updates and support are managed by Splunk. Legacy #8 / #9 are deprecated; #10 is archived — all three are listed last in the table below. Splunkbase Classic will be deactivated on 18 Feb 2026 — update any bookmarked classic links.

Palo Alto Networks — Additional GDI Option: Splunk Connect for Syslog (SC4S)

Palo Alto Networks is a recognised vendor in Splunk Connect for Syslog (SC4S), a community syslog-routing layer that's an alternative (or complement) to HEC/modular-input based GDI. SC4S auto-assigns sourcetypes and routes events to an index — it still needs a parsing TA installed on the search head for CIM/dashboards unless noted otherwise.
# Ingestion Path Type Support Owner Data Source Type Collected Sourcetype / Config Reference Link Notes — Usage
1 PAN-OS (NGFW / Panorama / Cortex Data Lake) SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) NGFW/Panorama/CDL syslog — legacy BSD default port 514, or IETF Framed on port 601 sourcetypes pan:log, pan:globalprotect, pan:traffic, pan:threat, pan:system, pan:config, pan:hipmatch, pan:correlation, pan:userid SC4S docs Alternative transport/routing layer to the direct syslog input already built into #1 (app/7523); still requires that TA on search heads for CIM parsing/dashboards. Useful if you already run SC4S for centralized syslog routing across many vendors.
2 Cortex XDR SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Cortex XDR / Cortex Data Lake syslog — requires TLS, IETF Framed, port 5425 sourcetypes pan:*, pan:xsoar SC4S docs SC4S docs still reference the deprecated #8 (app/2757) — pair with current-standard #1 (app/7523) instead for parsing.
3 Traps SC4S Syslog Routing (pairs with TA) Splunk Connect for Syslog (Community) Traps ESM syslog — legacy BSD format, default port 514 sourcetype pan:traps4 SC4S docs Pairs with #1 (app/7523) for parsing.
4 Prisma SD-WAN ION SC4S Syslog Routing (No App) Splunk Connect for Syslog (Community) Prisma SD-WAN ION flow, authentication & event syslogs (MSG format) sourcetypes prisma:sd-wan:flow, prisma:sd-wan:authentication, prisma:sd-wan:event SC4S docs No Splunkbase Add-on required. Distinct data source from Prisma Cloud (#6/#7, API-based audit logs) — Prisma SD-WAN ION is a separate networking product ingested purely via syslog.
Salesforce 6 apps
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for Salesforce Technical Add-On Splunk Supported Salesforce REST API — Event Log File data & SOQL object query output 7.0.0 31 Jul 2026 app/3549 CURRENT STANDARD. CIM-compatible inputs for use with Enterprise Security, PCI Compliance app, ITSI. v2.0.0 introduced breaking changes — always test upgrades in non-production before deploying.
2 Salesforce SOAR Connector Splunk Supported Salesforce object management API 3.0.1 21 Jul 2026 app/5930 For Splunk SOAR (response, not parsing): create/update/manage Salesforce objects as part of automated playbooks. FIPS compliant.
3 Splunk Add-on for Salesforce Streaming API Technical Add-On Splunk Works (Not Supported) Salesforce Streaming API — PushTopic, generic, platform & Change Data Capture (CDC) events 2.1.0 24 Jul 2026 app/5689 Near real-time push-based ingestion, complementary to #1's polled REST API collection. Not officially Splunk supported despite Splunk Works authorship.
4 CCX Extensions for Salesforce Technical Add-On (extension) 3rd party — CyberCX Enriches sourcetypes already ingested by #1 / #3 (login history, setup audit trail, log file, streaming login/report/security events) 1.0.6 24 Aug 2025 app/7174 Search-head-only extension adding field extraction & CIM compliance (Alerts, Authentication, Change, Data Access, IDS) on top of #1 and #3 — does not replace either add-on.
5 Salesforce Commerce Cloud Connector for CX Monitoring App 3rd-party dev (AIOPS Group Monitoring Team) Salesforce Commerce Cloud (SFCC) — logs, orders, products, pricebooks, inventory, eCDN, customer data 6.10.0 21 May 2026 app/6570 Broader CX-monitoring solution (not Salesforce CRM-specific): 360° monitoring with self-healing, 110+ real-time alerts, 200+ KPIs across the SFCC storefront stack.
6 Salesforce Monitoring App for Splunk App 3rd-party dev (Rojo Consultancy BV) Salesforce transactional & operational data (login history, platform/object stats, REST API usage) 1.0.0 24 Sep 2024 app/6579 NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date — listing shows "This app has no available versions." Out-of-the-box dashboards for login trends, org limits, and API insights once available.
Note: Salesforce is not a recognised vendor in Splunk Connect for Syslog (SC4S) — its data sources (REST/Streaming APIs) are not syslog-based, so SC4S provides no alternative GDI path here. All ingestion options above use API/HEC-based inputs instead.
Windows 10 active · 5 deprecated/archived
# Splunkbase App Type Support Owner Data Source Type Collected Latest Version Release Date Splunkbase Link Notes — Usage
1 Splunk Add-on for Microsoft Windows Technical Add-On Splunk Supported Windows Event Logs (Security/System/Application/etc.), performance counters, WMI, registry, Active Directory, DNS, DHCP, file system changes 11.0.1 12 Aug 2026 app/742 CURRENT STANDARD. Since v6.0.0 this TA has absorbed the standalone Splunk Add-on for Windows DNS and Splunk Add-on for Microsoft Active Directory — do not run those alongside v6.0.0+. CIM 5.x compatible. v5.0.0 introduced breaking changes — test upgrades in non-production first.
2 Splunk Asset and Risk Intelligence Technical Add-on For Windows Technical Add-On Splunk Supported Real-time Windows IT asset discovery & attribution (Splunk Asset and Risk Intelligence / SARI Edge Discovery) 1.2.0 17 Sep 2025 app/7214 Feeds Splunk's Asset and Risk Intelligence product — distinct from general log ingestion in TA #1; focused on asset inventory/attribution.
3 Windows Remote Management SOAR Connector Splunk Supported Windows Remote Management (WinRM) — remote command & script execution 3.0.0 app/5875 For Splunk SOAR (response, not parsing): run commands/scripts on remote Windows hosts via WinRM as part of automated playbooks.
4 TA-winfw Technology Addon for Windows Firewall Technical Add-On 3rd-party dev (Andreas Roth) Windows Firewall event logs 1.0.1 21 Aug 2024 app/3300 Dedicated parsing for Windows Firewall with Advanced Security logs, complementary to TA #1's general Windows Event Log coverage.
5 CCX Microsoft Windows Extensions (Defender for Endpoint and Sysmon) Technical Add-On (extension) 3rd party — CyberCX Enriches sourcetypes already ingested by TA #1 (Microsoft Defender for Endpoint & Sysmon events) 1.0.7 18 Sep 2024 app/6313 Search-head-only extension adding field extraction & CIM compliance on top of TA #1 — does not replace it.
6 Microsoft Windows Firewall Observability Technical Add-On 3rd-party dev (Amara Mohamed Traore) Windows host firewall traffic & configuration-change activity 2.0.0 20 Mar 2025 app/7790 CIM 6.x compliant; collects, parses and visualizes workstation/server firewall traffic and config changes with dedicated dashboards.
7 Windows Certificate Store Add-on for Splunk Technical Add-On 3rd-party dev (Crossrealms) Windows certificate store contents/metadata 1.0.2 22 Sep 2025 app/7013 Inventories certificates on Windows hosts for expiry tracking and compliance visibility.
8 Windows Security Operations Center App 3rd-party dev (Bojan Zdrnja) Consumes data ingested by TA #1 2.0.1 19 Sep 2025 app/647 Long-running community SOC dashboard app on top of TA #1 — correlation views for endpoint/security-relevant Windows events.
9 Add-On for Windows DNS Analytical Logging Technical Add-On 3rd-party dev (Hugh Kelley) Windows DNS Server analytical/diagnostic event logs 9 Jul 2023 app/4300 NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date. Last updated 2023 — evaluate TA #1's built-in DNS input first.
10 Windows Lateral Movement Detection Technical Add-On 3rd-party dev (community) Windows-based forensic inputs for lateral-movement threat hunting (built on SANS' 2018 "Hunt Evil" poster) 17 Sep 2025 app/4581 NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date — listing shows "This app has no available versions."
11 Splunk App for Windows Infrastructure App Splunk LLC (Archived) Consumed data from the legacy Windows TAs (superseded) 2.0.4 30 Aug 2021 app/1680 ARCHIVED / EOL. Splunk officially end-of-sold this app 31 Jul 2021 and end-of-lifed it 21 Oct 2021, refocusing on IT Essentials Work and IT Service Intelligence (ITSI) instead.
12 Splunk Add-on for Microsoft Windows DNS Technical Add-On Splunk LLC (Archived) Windows DNS Server logs 1.0.1 11 Oct 2016 app/3208 DEPRECATED / ARCHIVED. Fully absorbed into TA #1 as of v6.0.0 — do not install alongside TA #1 v6.0.0+.
13 TA for Microsoft Windows Defender Technical Add-On 3rd-party dev (Patrick O'Connell) Windows Defender antivirus/antimalware events 1.0.8 9 Dec 2021 app/3734 ARCHIVED. Consider CCX Microsoft Windows Extensions (#5) or TA #1's native Defender coverage instead.
14 Microsoft Windows DHCP addon for Splunk Technical Add-On 3rd-party dev (Nick Hills) Windows DHCP Server logs 1.2.0 17 Feb 2020 app/4359 ARCHIVED. No modern replacement identified on Splunkbase; evaluate custom inputs or generic file monitoring for DHCP server logs.
15 Splunk 5.x App for Microsoft Windows App Splunk Works (Archived) Legacy Windows infrastructure dashboards 5.0.2 12 Oct 2013 app/272 ARCHIVED — very old (2013). Long superseded by #11 and now by TA #1 + #8. Kept for historical reference only.
Note on SC4S: the SC4S "Microsoft" vendor entry covers only Cloud App Security (MCAS) — Microsoft's cloud-app CASB product, ingested as generic CEF via the Splunk Add-on for CEF, not Windows OS Event Logs. There is also an "Arcsight Microsoft Windows (CEF)" page filed under the Microfocus/ArcSight vendor category (generic CEF passthrough, no Windows-specific TA). Core Windows Event Log collection (Security/System/Application, Sysmon, etc.) is fundamentally agent-based — via Universal Forwarder + TA #1 — not syslog, since Windows has no native syslog daemon. Third-party tools (e.g. NXLog, Snare) can convert Windows Event Log to syslog for SC4S ingestion, but that is a host-side agent choice rather than a built-in SC4S "Windows" source.