Skip to main content
Cyberwatch Syslog Add-on for Splunk app icon

Cyberwatch Syslog Add-on for Splunk

Normalizes Cyberwatch vulnerability detection syslog events to CIM-compliant fields, enabling integration with Splunk Enterprise Security and the Vulnerabilities data model.Built by Thomas Dussossoy
splunk product badge

Default Version 2.0.0

September 15, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.1, 10.0, 9.1, 9.0

CIM Version: 8.x

Rating
5
(3)

Log in to rate this app

Support
Developer Supported
Ranking

#22 in Vulnerability Scanner

The Cyberwatch Syslog Add-on normalizes vulnerability detection data sent by Cyberwatch appliances over syslog into the Splunk Common Information Model. It provides field extractions, index-time configuration, and CIM compliance for the Vulnerabilities data model, enabling integration with Splunk Enterprise Security and IT operations workflows. The add-on handles the cyberwatch:syslog sourcetype and includes timestamp recognition, field extraction rules, and CIM tagging to ensure vulnerability events are properly structured for downstream analysis. It contains configuration files only, with no custom scripts or user interface components.