Apps and Technical Add-Ons available on Splunkbase, organised by vendor — click a tab below to jump to a vendor's list.
| # | Ingestion Path | Type | Support Owner | Data Source Type Collected | Sourcetype / Config | Reference Link | Notes — Usage |
|---|---|---|---|---|---|---|---|
| 1 | Alcatel Switch (via Splunk Connect for Syslog) | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Alcatel switch syslogs — legacy BSD format, default port 514, MSG-format based filter | sourcetype alcatel:switch → index netops |
SC4S docs | No Splunkbase Add-on required — SC4S's built-in filter recognises Alcatel switch syslog and assigns alcatel:switch automatically. If a dedicated parsing TA is ever published on Splunkbase, add it here as a normal row. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for Amazon Web Services (AWS) | Technical Add-On | Splunk Supported | AWS Config, EC2/EBS metadata, Inspector, CloudTrail, CloudWatch (logs/metrics/billing), S3/CloudFront/ELB access logs, generic S3/Kinesis/SQS, Amazon Security Lake | 8.2.1 | 30 Jul 2026 | app/1876 | CURRENT STANDARD. Modular-input TA, CIM 5.x compatible. From v7.0.0 it has absorbed the Splunk Add-on for Amazon Security Lake (uninstall that add-on before upgrading to avoid duplication). Splunk Cloud users should also evaluate the newer Splunk Data Inputs (formerly Data Manager) onboarding flow, which co-exists with this TA. |
| 2 | Splunk App for AWS Security Dashboards | App | Splunk Supported | Consumes data ingested by TA #1 | 1.3.0 | 7 Feb 2026 | app/6311 | Visualization layer: pre-built security dashboards on top of TA #1. Search-head tier; requires TA #1. |
| 3 | Splunk Add-on for AWS Security Hub | Technical Add-On | Splunk Supported | AWS Security Hub — real-time findings | 1.1.1 | — | app/8642 | PREMIUM. Requires a subscription via "AWS Security Hub Extended." Converts real-time Security Hub events into findings/intermediate findings for Splunk Enterprise Security — separate from the general-purpose TA #1. |
| 4 | AWS Service Connectors (SOAR) | SOAR Connector | Splunk Supported | AWS service management APIs — containment & investigative playbook actions | 2.x | Jul–Aug 2026 | See notes | For Splunk SOAR (response, not parsing). Splunk publishes this as 13 separate per-service connector apps, consolidated here for brevity: EC2 · GuardDuty · S3 · CloudTrail · IAM · Security Token Service · Athena · Systems Manager · Security Hub · Lambda · WAF V2 · Inspector · DynamoDB |
| 5 | CCX Add-on for AWS Products | Technical Add-On (extension) | 3rd party — CyberCX | Enriches sourcetypes already ingested by TA #1 (Network Firewall, WAF, S3 VPC Flow, Macie, API Gateway Access Logs, Security Hub Custom) | 1.2.9 | 4 Aug 2026 | app/6542 | Search-head-only extension adding field extraction & CIM compliance (Alert, Change, Network Traffic, Web) on top of TA #1 — does not replace it. Ingest via SQS-based S3 custom data type or syslog. |
| 6 | AWS Web Application Firewall Add-on | Technical Add-On | 3rd-party dev (Hurricane Labs) | AWS WAF logs via Kinesis Firehose (JSON) | 1.0.6 | 16 Dec 2025 | app/4714 | CIM 4.0+ compliant, Enterprise Security-ready. Includes a guide for routing AWS WAF logs to Splunk via Kinesis Firehose. |
| 7 | AWS Trusted Advisor Aggregator | App | 3rd-party dev (community, built on Hurricane Labs foundations) | AWS Trusted Advisor recommendations across one or more accounts (cost, performance, security) | 1.2.1 | 27 Dec 2024 | app/4207 | Pre-built multi-account dashboard; supports AWS Access/Secret keys, instance-profile credentials, or AssumeRole for cross-account data collection. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Check Point Firewall | SOAR Connector | Splunk Supported | Check Point Firewall management API — endpoint & network containment actions | 4.0.0 | 4 Aug 2026 | app/5777 | For Splunk SOAR (response, not parsing): block/unblock IP, add/remove host from group, and other containment playbook actions against Check Point firewalls. FIPS compliant. |
| 2 | Check Point App for Splunk | Technical Add-On | Check Point (Not Supported) | Firewall, endpoint, mobile & cloud logs via Check Point Log Exporter (all Check Point technologies/platforms) | 1.1.6 | 6 Jul 2026 | app/4293 | CURRENT STANDARD. Primary parsing TA: CIM-compatible, integrates with Enterprise Security & SmartEvent dashboards (General Overview, Threat Prevention, Cyber Attack View), MITRE ATT&CK analytics for SandBlast malware findings. Uses Log Exporter (syslog) — see Check Point sk122323. |
| 3 | Check Point Exposure Management (Cyberint) | Technical Add-On | 3rd-party dev (bensa bensa) | Cyberint / Argos Edge threat intelligence — alerts, attack tools, phishing & fraud detections | 1.2.0 | 4 Aug 2026 | app/7117 | Fetches enriched, intelligence-driven threat data with automatic incident-status sync; ships pre-built dashboards for investigation. |
| 4 | Splunk Add-on for Check Point Log Exporter | Technical Add-On | Splunk LLC (Archived) | Check Point Log Exporter over syslog (RFC5424) | 1.2.0 | 15 Feb 2024 | app/5478 | ARCHIVED. Splunk-built TA specifically for Log Exporter syslog ingestion (sourcetype cp_log:syslog); Splunkbase lists it as an archived add-on. Use #2 (app/4293) for parsing instead — see the SC4S GDI option below for the Log Exporter transport layer. |
| # | Ingestion Path | Type | Support Owner | Data Source Type Collected | Sourcetype / Config | Reference Link | Notes — Usage |
|---|---|---|---|---|---|---|---|
| 1 | Firewall OS (direct syslog) | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Native/raw firewall syslog output (no Log Exporter involved) | sourcetype cp_log:fw:syslog → index netops |
SC4S docs | No Splunkbase Add-on required — for devices sending direct syslog without Check Point's Log Exporter. |
| 2 | Log Exporter (Syslog / RFC5424) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Log Exporter output over IETF RFC5424 syslog, port 514/TCP | sourcetype cp_log:syslog → index netops |
SC4S docs | SC4S references the now-ARCHIVED #4 (app/5478); pair with #2 (app/4293) for parsing instead. SC4S notes Check Point's own Log Exporter config template was defective as of 2/1/2022 — use SC4S's corrected config. |
| 3 | Log Exporter (Splunk legacy format) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Legacy "Splunk format" Log Exporter output (non-RFC3164 conformant) | sourcetype cp_log |
SC4S docs | LEGACY — avoid for new deployments. SC4S docs explicitly recommend Log Exporter (Syslog) above instead. Pairs with #2 (app/4293). |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for Palo Alto Networks | Technical Add-On | Splunk Supported | Cortex XDR, IoT Security, Firewalls (NGFW), Panorama, Strata Logging Service | 3.1.0 | 22 May 2026 | app/7523 | CURRENT STANDARD. Official parsing TA: modular inputs for IoT Security & Cortex XDR, CIM 5.x normalisation, health-check monitoring dashboard, latest PAN-OS support. Deploy on indexers / heavy forwarders. |
| 2 | Splunk App for Palo Alto Networks | App | Splunk LLC (Supported) | Consumes data ingested by TA #1 (firewall, Panorama, XDR, IoT, SLS) | 1.0.1 | 14 Nov 2024 | app/7505 | Visualization layer: security reporting & analysis dashboards correlating app/user activity across network & security infrastructure. Search-head tier; requires TA #1. |
| 3 | Palo Alto API Inputs Add On | Technical Add-On | 3rd-party dev (Edlyn Liew) | Logs & telemetry from PAN devices via API (alternative to syslog/HEC) | 1.0.16 | 4 Dec 2025 | app/8283 | Use where syslog forwarding isn't feasible (firewalls behind NAT / restricted networks) or extra API metadata is needed; supports custom API endpoint scripts. |
| 4 | CCX Palo Alto Cortex XDR (CEF) | Technical Add-On | 3rd party — CyberCX | Cortex XDR syslog (CEF) forwarded from Cortex Data Lake via syslog server | 1.0.2 | 29 Aug 2025 | app/6326 | Field-extraction bundle mapping XDR CEF logs to CIM datamodels: Network Traffic, Change, Malware, Alerts, IDS. Not Splunk supported. |
| 5 | Palo Alto Cortex XDR | SOAR Connector | SOAR Community | Cortex XDR API — incidents, endpoints | 1.2.1 | 28 Apr 2025 | app/6046 | For Splunk SOAR (response, not parsing): on-poll ingest, list endpoints, block/allow hash, quarantine / unquarantine device, get incident details. |
| 6 | Prisma Cloud Audit Input | Technical Add-On (input) | 3rd-party dev (Brett Adams) | Prisma Cloud audit logs (API pull) | 1.0.2 | 10 Aug 2025 | app/6379 | Pulls the Prisma Cloud audit trail into Splunk for admin / compliance visibility. |
| 7 | Add-on for Prisma Cloud Audit | Technical Add-On (input) | 3rd-party dev (Rotimi Akinbobola) | Audit events from Prisma Cloud | 1.0.1 | 21 Apr 2025 | app/7700 | Alternative Prisma Cloud audit fetcher — compare features against #6 before selecting. |
| 8 | Palo Alto Networks Add-on for Splunk (Splunk_TA_paloalto) | Technical Add-On | Palo Alto Networks | NGFW, Panorama, Traps ESM; also Aperture / SaaS Security, Cortex XDR, MineMeld / AutoFocus | 8.1.3 | 24 May 2024 | app/2757 | DEPRECATED / ARCHIVED. Legacy PAN-owned TA. Migrate to #1 (Splunk-supported); note revised CIM mapping, macros, and input config changes during migration. |
| 9 | Palo Alto Networks App for Splunk (SplunkforPaloAltoNetworks) | App | Palo Alto Networks | Consumes legacy TA #8 data (firewall, GlobalProtect, WildFire, Traps, Aperture) | 8.1.3 | 24 May 2024 | app/491 | DEPRECATED / ARCHIVED. Legacy dashboards: adversary attacks, incidents, SaaS usage, system health, config audit, malware, GlobalProtect VPN. Migrate to #2. |
| 10 | CCX Add-on for Palo Alto Networks (PAN IOT) | Technical Add-On | 3rd party — CyberCX | IoT Security API — alert events, detections, vulnerabilities | 1.0.0 | 27 Feb 2024 | app/7250 | ARCHIVED. CIM-compliant extractions (Alert, Endpoint, Network Traffic, IDS, Vulnerabilities). Superseded by the native IoT input in TA #1. |
#1 current standard · #8 / #9 legacy, migrate off · #3 API-based alternative
#1 native SLS input · #4 CEF-via-syslog extraction
#1 API modular input · #4 CEF syslog parsing · #5 SOAR response actions
#1 native input · #10 archived CyberCX alternative
#6 / #7 audit logs. Prisma Cloud Compute (Twistlock) App — app/4555 by Palo Alto Networks — covers incidents & forensics via the Compute API (verify latest version on the listing).
| # | Ingestion Path | Type | Support Owner | Data Source Type Collected | Sourcetype / Config | Reference Link | Notes — Usage |
|---|---|---|---|---|---|---|---|
| 1 | PAN-OS (NGFW / Panorama / Cortex Data Lake) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | NGFW/Panorama/CDL syslog — legacy BSD default port 514, or IETF Framed on port 601 | sourcetypes pan:log, pan:globalprotect, pan:traffic, pan:threat, pan:system, pan:config, pan:hipmatch, pan:correlation, pan:userid |
SC4S docs | Alternative transport/routing layer to the direct syslog input already built into #1 (app/7523); still requires that TA on search heads for CIM parsing/dashboards. Useful if you already run SC4S for centralized syslog routing across many vendors. |
| 2 | Cortex XDR | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Cortex XDR / Cortex Data Lake syslog — requires TLS, IETF Framed, port 5425 | sourcetypes pan:*, pan:xsoar |
SC4S docs | SC4S docs still reference the deprecated #8 (app/2757) — pair with current-standard #1 (app/7523) instead for parsing. |
| 3 | Traps | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Traps ESM syslog — legacy BSD format, default port 514 | sourcetype pan:traps4 |
SC4S docs | Pairs with #1 (app/7523) for parsing. |
| 4 | Prisma SD-WAN ION | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Prisma SD-WAN ION flow, authentication & event syslogs (MSG format) | sourcetypes prisma:sd-wan:flow, prisma:sd-wan:authentication, prisma:sd-wan:event |
SC4S docs | No Splunkbase Add-on required. Distinct data source from Prisma Cloud (#6/#7, API-based audit logs) — Prisma SD-WAN ION is a separate networking product ingested purely via syslog. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for Salesforce | Technical Add-On | Splunk Supported | Salesforce REST API — Event Log File data & SOQL object query output | 7.0.0 | 31 Jul 2026 | app/3549 | CURRENT STANDARD. CIM-compatible inputs for use with Enterprise Security, PCI Compliance app, ITSI. v2.0.0 introduced breaking changes — always test upgrades in non-production before deploying. |
| 2 | Salesforce | SOAR Connector | Splunk Supported | Salesforce object management API | 3.0.1 | 21 Jul 2026 | app/5930 | For Splunk SOAR (response, not parsing): create/update/manage Salesforce objects as part of automated playbooks. FIPS compliant. |
| 3 | Splunk Add-on for Salesforce Streaming API | Technical Add-On | Splunk Works (Not Supported) | Salesforce Streaming API — PushTopic, generic, platform & Change Data Capture (CDC) events | 2.1.0 | 24 Jul 2026 | app/5689 | Near real-time push-based ingestion, complementary to #1's polled REST API collection. Not officially Splunk supported despite Splunk Works authorship. |
| 4 | CCX Extensions for Salesforce | Technical Add-On (extension) | 3rd party — CyberCX | Enriches sourcetypes already ingested by #1 / #3 (login history, setup audit trail, log file, streaming login/report/security events) | 1.0.6 | 24 Aug 2025 | app/7174 | Search-head-only extension adding field extraction & CIM compliance (Alerts, Authentication, Change, Data Access, IDS) on top of #1 and #3 — does not replace either add-on. |
| 5 | Salesforce Commerce Cloud Connector for CX Monitoring | App | 3rd-party dev (AIOPS Group Monitoring Team) | Salesforce Commerce Cloud (SFCC) — logs, orders, products, pricebooks, inventory, eCDN, customer data | 6.10.0 | 21 May 2026 | app/6570 | Broader CX-monitoring solution (not Salesforce CRM-specific): 360° monitoring with self-healing, 110+ real-time alerts, 200+ KPIs across the SFCC storefront stack. |
| 6 | Salesforce Monitoring App for Splunk | App | 3rd-party dev (Rojo Consultancy BV) | Salesforce transactional & operational data (login history, platform/object stats, REST API usage) | 1.0.0 | 24 Sep 2024 | app/6579 | NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date — listing shows "This app has no available versions." Out-of-the-box dashboards for login trends, org limits, and API insights once available. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for Microsoft Windows | Technical Add-On | Splunk Supported | Windows Event Logs (Security/System/Application/etc.), performance counters, WMI, registry, Active Directory, DNS, DHCP, file system changes | 11.0.1 | 12 Aug 2026 | app/742 | CURRENT STANDARD. Since v6.0.0 this TA has absorbed the standalone Splunk Add-on for Windows DNS and Splunk Add-on for Microsoft Active Directory — do not run those alongside v6.0.0+. CIM 5.x compatible. v5.0.0 introduced breaking changes — test upgrades in non-production first. |
| 2 | Splunk Asset and Risk Intelligence Technical Add-on For Windows | Technical Add-On | Splunk Supported | Real-time Windows IT asset discovery & attribution (Splunk Asset and Risk Intelligence / SARI Edge Discovery) | 1.2.0 | 17 Sep 2025 | app/7214 | Feeds Splunk's Asset and Risk Intelligence product — distinct from general log ingestion in TA #1; focused on asset inventory/attribution. |
| 3 | Windows Remote Management | SOAR Connector | Splunk Supported | Windows Remote Management (WinRM) — remote command & script execution | 3.0.0 | — | app/5875 | For Splunk SOAR (response, not parsing): run commands/scripts on remote Windows hosts via WinRM as part of automated playbooks. |
| 4 | TA-winfw Technology Addon for Windows Firewall | Technical Add-On | 3rd-party dev (Andreas Roth) | Windows Firewall event logs | 1.0.1 | 21 Aug 2024 | app/3300 | Dedicated parsing for Windows Firewall with Advanced Security logs, complementary to TA #1's general Windows Event Log coverage. |
| 5 | CCX Microsoft Windows Extensions (Defender for Endpoint and Sysmon) | Technical Add-On (extension) | 3rd party — CyberCX | Enriches sourcetypes already ingested by TA #1 (Microsoft Defender for Endpoint & Sysmon events) | 1.0.7 | 18 Sep 2024 | app/6313 | Search-head-only extension adding field extraction & CIM compliance on top of TA #1 — does not replace it. |
| 6 | Microsoft Windows Firewall Observability | Technical Add-On | 3rd-party dev (Amara Mohamed Traore) | Windows host firewall traffic & configuration-change activity | 2.0.0 | 20 Mar 2025 | app/7790 | CIM 6.x compliant; collects, parses and visualizes workstation/server firewall traffic and config changes with dedicated dashboards. |
| 7 | Windows Certificate Store Add-on for Splunk | Technical Add-On | 3rd-party dev (Crossrealms) | Windows certificate store contents/metadata | 1.0.2 | 22 Sep 2025 | app/7013 | Inventories certificates on Windows hosts for expiry tracking and compliance visibility. |
| 8 | Windows Security Operations Center | App | 3rd-party dev (Bojan Zdrnja) | Consumes data ingested by TA #1 | 2.0.1 | 19 Sep 2025 | app/647 | Long-running community SOC dashboard app on top of TA #1 — correlation views for endpoint/security-relevant Windows events. |
| 9 | Add-On for Windows DNS Analytical Logging | Technical Add-On | 3rd-party dev (Hugh Kelley) | Windows DNS Server analytical/diagnostic event logs | — | 9 Jul 2023 | app/4300 | NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date. Last updated 2023 — evaluate TA #1's built-in DNS input first. |
| 10 | Windows Lateral Movement Detection | Technical Add-On | 3rd-party dev (community) | Windows-based forensic inputs for lateral-movement threat hunting (built on SANS' 2018 "Hunt Evil" poster) | — | 17 Sep 2025 | app/4581 | NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date — listing shows "This app has no available versions." |
| 11 | Splunk App for Windows Infrastructure | App | Splunk LLC (Archived) | Consumed data from the legacy Windows TAs (superseded) | 2.0.4 | 30 Aug 2021 | app/1680 | ARCHIVED / EOL. Splunk officially end-of-sold this app 31 Jul 2021 and end-of-lifed it 21 Oct 2021, refocusing on IT Essentials Work and IT Service Intelligence (ITSI) instead. |
| 12 | Splunk Add-on for Microsoft Windows DNS | Technical Add-On | Splunk LLC (Archived) | Windows DNS Server logs | 1.0.1 | 11 Oct 2016 | app/3208 | DEPRECATED / ARCHIVED. Fully absorbed into TA #1 as of v6.0.0 — do not install alongside TA #1 v6.0.0+. |
| 13 | TA for Microsoft Windows Defender | Technical Add-On | 3rd-party dev (Patrick O'Connell) | Windows Defender antivirus/antimalware events | 1.0.8 | 9 Dec 2021 | app/3734 | ARCHIVED. Consider CCX Microsoft Windows Extensions (#5) or TA #1's native Defender coverage instead. |
| 14 | Microsoft Windows DHCP addon for Splunk | Technical Add-On | 3rd-party dev (Nick Hills) | Windows DHCP Server logs | 1.2.0 | 17 Feb 2020 | app/4359 | ARCHIVED. No modern replacement identified on Splunkbase; evaluate custom inputs or generic file monitoring for DHCP server logs. |
| 15 | Splunk 5.x App for Microsoft Windows | App | Splunk Works (Archived) | Legacy Windows infrastructure dashboards | 5.0.2 | 12 Oct 2013 | app/272 | ARCHIVED — very old (2013). Long superseded by #11 and now by TA #1 + #8. Kept for historical reference only. |