April 9, 2026
Zyxel Add-on for Splunk
The Zyxel Add-on for Splunk Enterprise (TA_Zyxel_Splunk) sets the correct sourcetype, fields used for identifying data from Zyxel firewall using Splunk® Enterprise & Splunk® Cloud for all the categories of logs. This also allows Splunk software administrators to map Zyxel firewall device events to the Splunk CIM.Built by Avotrix IncSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
Log in to rate this app
The Zyxel Add-on for Splunk Enterprise (TA_Zyxel_Splunk) sets the correct sourcetype, fields used for identifying data from Zyxel firewall using Splunk® Enterprise & Splunk® Cloud for all the categories of logs. This also allows Splunk software administrators to map Zyxel firewall device events to the Splunk CIM. Install this Add-On on your Heavy forwarder indexer and search head. Install the Zyxel firewall Splunk App (Avo_Zyxel_Firewall_Monitor) https://classic.splunkbase.splunk.com/app/4907/ on your search head and get an insight into firewall data via dashboards, data models, reports, alerts, and security use cases.
Log in to report this app listing.