September 15, 2026
Cyberwatch Syslog Add-on for Splunk
Normalizes Cyberwatch vulnerability detection syslog events to CIM-compliant fields, enabling integration with Splunk Enterprise Security and the Vulnerabilities data model.Built by Thomas DussossoySplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.1, 10.0, 9.1, 9.0
CIM Version: 8.x
Log in to rate this app
#22 in Vulnerability Scanner
The Cyberwatch Syslog Add-on normalizes vulnerability detection data sent by Cyberwatch appliances over syslog into the Splunk Common Information Model. It provides field extractions, index-time configuration, and CIM compliance for the Vulnerabilities data model, enabling integration with Splunk Enterprise Security and IT operations workflows. The add-on handles the cyberwatch:syslog sourcetype and includes timestamp recognition, field extraction rules, and CIM tagging to ensure vulnerability events are properly structured for downstream analysis. It contains configuration files only, with no custom scripts or user interface components.
Log in to report this app listing.