Apps and Technical Add-Ons available on Splunkbase, organised by vendor — click a tab below to jump to a vendor's list.
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for Palo Alto Networks | Technical Add-On | Splunk Supported | Cortex XDR, IoT Security, Firewalls (NGFW), Panorama, Strata Logging Service | 3.1.0 | 22 May 2026 | app/7523 | CURRENT STANDARD. Official parsing TA: modular inputs for IoT Security & Cortex XDR, CIM 5.x normalisation, health-check monitoring dashboard, latest PAN-OS support. Deploy on indexers / heavy forwarders. |
| 2 | Splunk App for Palo Alto Networks | App | Splunk LLC (Supported) | Consumes data ingested by TA #1 (firewall, Panorama, XDR, IoT, SLS) | 1.0.1 | 14 Nov 2024 | app/7505 | Visualization layer: security reporting & analysis dashboards correlating app/user activity across network & security infrastructure. Search-head tier; requires TA #1. |
| 3 | Palo Alto API Inputs Add On | Technical Add-On | 3rd-party dev (Edlyn Liew) | Logs & telemetry from PAN devices via API (alternative to syslog/HEC) | 1.0.16 | 4 Dec 2025 | app/8283 | Use where syslog forwarding isn't feasible (firewalls behind NAT / restricted networks) or extra API metadata is needed; supports custom API endpoint scripts. |
| 4 | CCX Palo Alto Cortex XDR (CEF) | Technical Add-On | 3rd party — CyberCX | Cortex XDR syslog (CEF) forwarded from Cortex Data Lake via syslog server | 1.0.2 | 29 Aug 2025 | app/6326 | Field-extraction bundle mapping XDR CEF logs to CIM datamodels: Network Traffic, Change, Malware, Alerts, IDS. Not Splunk supported. |
| 5 | Palo Alto Cortex XDR | SOAR Connector | SOAR Community | Cortex XDR API — incidents, endpoints | 1.2.1 | 28 Apr 2025 | app/6046 | For Splunk SOAR (response, not parsing): on-poll ingest, list endpoints, block/allow hash, quarantine / unquarantine device, get incident details. |
| 6 | Prisma Cloud Audit Input | Technical Add-On (input) | 3rd-party dev (Brett Adams) | Prisma Cloud audit logs (API pull) | 1.0.2 | 10 Aug 2025 | app/6379 | Pulls the Prisma Cloud audit trail into Splunk for admin / compliance visibility. |
| 7 | Add-on for Prisma Cloud Audit | Technical Add-On (input) | 3rd-party dev (Rotimi Akinbobola) | Audit events from Prisma Cloud | 1.0.1 | 21 Apr 2025 | app/7700 | Alternative Prisma Cloud audit fetcher — compare features against #6 before selecting. |
| 8 | Palo Alto Networks Add-on for Splunk (Splunk_TA_paloalto) | Technical Add-On | Palo Alto Networks | NGFW, Panorama, Traps ESM; also Aperture / SaaS Security, Cortex XDR, MineMeld / AutoFocus | 8.1.3 | 24 May 2024 | app/2757 | DEPRECATED / ARCHIVED. Legacy PAN-owned TA. Migrate to #1 (Splunk-supported); note revised CIM mapping, macros, and input config changes during migration. |
| 9 | Palo Alto Networks App for Splunk (SplunkforPaloAltoNetworks) | App | Palo Alto Networks | Consumes legacy TA #8 data (firewall, GlobalProtect, WildFire, Traps, Aperture) | 8.1.3 | 24 May 2024 | app/491 | DEPRECATED / ARCHIVED. Legacy dashboards: adversary attacks, incidents, SaaS usage, system health, config audit, malware, GlobalProtect VPN. Migrate to #2. |
| 10 | CCX Add-on for Palo Alto Networks (PAN IOT) | Technical Add-On | 3rd party — CyberCX | IoT Security API — alert events, detections, vulnerabilities | 1.0.0 | 27 Feb 2024 | app/7250 | ARCHIVED. CIM-compliant extractions (Alert, Endpoint, Network Traffic, IDS, Vulnerabilities). Superseded by the native IoT input in TA #1. |
#1 current standard · #8 / #9 legacy, migrate off · #3 API-based alternative
#1 native SLS input · #4 CEF-via-syslog extraction
#1 API modular input · #4 CEF syslog parsing · #5 SOAR response actions
#1 native input · #10 archived CyberCX alternative
#6 / #7 audit logs. Prisma Cloud Compute (Twistlock) App — app/4555 by Palo Alto Networks — covers incidents & forensics via the Compute API (verify latest version on the listing).
| # | Ingestion Path | Type | Support Owner | Data Source Type Collected | Sourcetype / Config | Reference Link | Notes — Usage |
|---|---|---|---|---|---|---|---|
| 1 | PAN-OS (NGFW / Panorama / Cortex Data Lake) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | NGFW/Panorama/CDL syslog — legacy BSD default port 514, or IETF Framed on port 601 | sourcetypes pan:log, pan:globalprotect, pan:traffic, pan:threat, pan:system, pan:config, pan:hipmatch, pan:correlation, pan:userid |
SC4S docs | Alternative transport/routing layer to the direct syslog input already built into #1 (app/7523); still requires that TA on search heads for CIM parsing/dashboards. Useful if you already run SC4S for centralized syslog routing across many vendors. |
| 2 | Cortex XDR | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Cortex XDR / Cortex Data Lake syslog — requires TLS, IETF Framed, port 5425 | sourcetypes pan:*, pan:xsoar |
SC4S docs | SC4S docs still reference the deprecated #8 (app/2757) — pair with current-standard #1 (app/7523) instead for parsing. |
| 3 | Traps | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Traps ESM syslog — legacy BSD format, default port 514 | sourcetype pan:traps4 |
SC4S docs | Pairs with #1 (app/7523) for parsing. |
| 4 | Prisma SD-WAN ION | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Prisma SD-WAN ION flow, authentication & event syslogs (MSG format) | sourcetypes prisma:sd-wan:flow, prisma:sd-wan:authentication, prisma:sd-wan:event |
SC4S docs | No Splunkbase Add-on required. Distinct data source from Prisma Cloud (#6/#7, API-based audit logs) — Prisma SD-WAN ION is a separate networking product ingested purely via syslog. |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Check Point Firewall | SOAR Connector | Splunk Supported | Check Point Firewall management API — endpoint & network containment actions | 4.0.0 | 4 Aug 2026 | app/5777 | For Splunk SOAR (response, not parsing): block/unblock IP, add/remove host from group, and other containment playbook actions against Check Point firewalls. FIPS compliant. |
| 2 | Check Point App for Splunk | Technical Add-On | Check Point (Not Supported) | Firewall, endpoint, mobile & cloud logs via Check Point Log Exporter (all Check Point technologies/platforms) | 1.1.6 | 6 Jul 2026 | app/4293 | CURRENT STANDARD. Primary parsing TA: CIM-compatible, integrates with Enterprise Security & SmartEvent dashboards (General Overview, Threat Prevention, Cyber Attack View), MITRE ATT&CK analytics for SandBlast malware findings. Uses Log Exporter (syslog) — see Check Point sk122323. |
| 3 | Check Point Exposure Management (Cyberint) | Technical Add-On | 3rd-party dev (bensa bensa) | Cyberint / Argos Edge threat intelligence — alerts, attack tools, phishing & fraud detections | 1.2.0 | 4 Aug 2026 | app/7117 | Fetches enriched, intelligence-driven threat data with automatic incident-status sync; ships pre-built dashboards for investigation. |
| 4 | Splunk Add-on for Check Point Log Exporter | Technical Add-On | Splunk LLC (Archived) | Check Point Log Exporter over syslog (RFC5424) | 1.2.0 | 15 Feb 2024 | app/5478 | ARCHIVED. Splunk-built TA specifically for Log Exporter syslog ingestion (sourcetype cp_log:syslog); Splunkbase lists it as an archived add-on. Use #2 (app/4293) for parsing instead — see the SC4S GDI option below for the Log Exporter transport layer. |
| # | Ingestion Path | Type | Support Owner | Data Source Type Collected | Sourcetype / Config | Reference Link | Notes — Usage |
|---|---|---|---|---|---|---|---|
| 1 | Firewall OS (direct syslog) | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Native/raw firewall syslog output (no Log Exporter involved) | sourcetype cp_log:fw:syslog → index netops |
SC4S docs | No Splunkbase Add-on required — for devices sending direct syslog without Check Point's Log Exporter. |
| 2 | Log Exporter (Syslog / RFC5424) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Log Exporter output over IETF RFC5424 syslog, port 514/TCP | sourcetype cp_log:syslog → index netops |
SC4S docs | SC4S references the now-ARCHIVED #4 (app/5478); pair with #2 (app/4293) for parsing instead. SC4S notes Check Point's own Log Exporter config template was defective as of 2/1/2022 — use SC4S's corrected config. |
| 3 | Log Exporter (Splunk legacy format) | SC4S Syslog Routing (pairs with TA) | Splunk Connect for Syslog (Community) | Legacy "Splunk format" Log Exporter output (non-RFC3164 conformant) | sourcetype cp_log |
SC4S docs | LEGACY — avoid for new deployments. SC4S docs explicitly recommend Log Exporter (Syslog) above instead. Pairs with #2 (app/4293). |
| # | Splunkbase App | Type | Support Owner | Data Source Type Collected | Latest Version | Release Date | Splunkbase Link | Notes — Usage |
|---|---|---|---|---|---|---|---|---|
| 1 | Splunk Add-on for Salesforce | Technical Add-On | Splunk Supported | Salesforce REST API — Event Log File data & SOQL object query output | 7.0.0 | 31 Jul 2026 | app/3549 | CURRENT STANDARD. CIM-compatible inputs for use with Enterprise Security, PCI Compliance app, ITSI. v2.0.0 introduced breaking changes — always test upgrades in non-production before deploying. |
| 2 | Salesforce | SOAR Connector | Splunk Supported | Salesforce object management API | 3.0.1 | 21 Jul 2026 | app/5930 | For Splunk SOAR (response, not parsing): create/update/manage Salesforce objects as part of automated playbooks. FIPS compliant. |
| 3 | Splunk Add-on for Salesforce Streaming API | Technical Add-On | Splunk Works (Not Supported) | Salesforce Streaming API — PushTopic, generic, platform & Change Data Capture (CDC) events | 2.1.0 | 24 Jul 2026 | app/5689 | Near real-time push-based ingestion, complementary to #1's polled REST API collection. Not officially Splunk supported despite Splunk Works authorship. |
| 4 | CCX Extensions for Salesforce | Technical Add-On (extension) | 3rd party — CyberCX | Enriches sourcetypes already ingested by #1 / #3 (login history, setup audit trail, log file, streaming login/report/security events) | 1.0.6 | 24 Aug 2025 | app/7174 | Search-head-only extension adding field extraction & CIM compliance (Alerts, Authentication, Change, Data Access, IDS) on top of #1 and #3 — does not replace either add-on. |
| 5 | Salesforce Commerce Cloud Connector for CX Monitoring | App | 3rd-party dev (AIOPS Group Monitoring Team) | Salesforce Commerce Cloud (SFCC) — logs, orders, products, pricebooks, inventory, eCDN, customer data | 6.10.0 | 21 May 2026 | app/6570 | Broader CX-monitoring solution (not Salesforce CRM-specific): 360° monitoring with self-healing, 110+ real-time alerts, 200+ KPIs across the SFCC storefront stack. |
| 6 | Salesforce Monitoring App for Splunk | App | 3rd-party dev (Rojo Consultancy BV) | Salesforce transactional & operational data (login history, platform/object stats, REST API usage) | 1.0.0 | 24 Sep 2024 | app/6579 | NO DOWNLOADABLE VERSION LISTED on Splunkbase as of compile date — listing shows "This app has no available versions." Out-of-the-box dashboards for login trends, org limits, and API insights once available. |
| # | Ingestion Path | Type | Support Owner | Data Source Type Collected | Sourcetype / Config | Reference Link | Notes — Usage |
|---|---|---|---|---|---|---|---|
| 1 | Alcatel Switch (via Splunk Connect for Syslog) | SC4S Syslog Routing (No App) | Splunk Connect for Syslog (Community) | Alcatel switch syslogs — legacy BSD format, default port 514, MSG-format based filter | sourcetype alcatel:switch → index netops |
SC4S docs | No Splunkbase Add-on required — SC4S's built-in filter recognises Alcatel switch syslog and assigns alcatel:switch automatically. If a dedicated parsing TA is ever published on Splunkbase, add it here as a normal row. |