Default Version 1.0.11
August 21, 2025
August 21, 2025
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3
CIM Version: 6.x
Log in to rate this app
#2 in Network Security
#26 in Security, Fraud & Compliance
This add-on parses open-source Zeek data in JSON and TSV formats, and populates it through into the CIM data model. Compatible with the dashboards and visualizations in the Corelight App for Splunk. Previously maintained by Splunk as the "Splunk Add-on for Zeek aka Bro", now maintained by Corelight as part of its ongoing support for the Zeek project.
Log in to report this app listing.