Skip to main content
Zyxel Add-on for Splunk app icon

Zyxel Add-on for Splunk

The Zyxel Add-on for Splunk Enterprise (TA_Zyxel_Splunk) sets the correct sourcetype, fields used for identifying data from Zyxel firewall using Splunk® Enterprise & Splunk® Cloud for all the categories of logs. This also allows Splunk software administrators to map Zyxel firewall device events to the Splunk CIM.Built by Avotrix Inc
splunk product badge

Default Version 2.0.3

April 9, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

Rating
5
(1)

Log in to rate this app

Support
Developer Supported

The Zyxel Add-on for Splunk Enterprise (TA_Zyxel_Splunk) sets the correct sourcetype, fields used for identifying data from Zyxel firewall using Splunk® Enterprise & Splunk® Cloud for all the categories of logs. This also allows Splunk software administrators to map Zyxel firewall device events to the Splunk CIM. Install this Add-On on your Heavy forwarder indexer and search head. Install the Zyxel firewall Splunk App (Avo_Zyxel_Firewall_Monitor) https://classic.splunkbase.splunk.com/app/4907/ on your search head and get an insight into firewall data via dashboards, data models, reports, alerts, and security use cases.