Skip to main content
Microsoft Windows Firewall Observability app icon

Microsoft Windows Firewall Observability

This App was designed to Collect, parse, normalise and visualise Windows Defender Firewall activity: the connection log (pfirewall.log), the configuration and policy change events, the Windows Filtering Platform audit events that attribute a connection to the binary that opened it, and - with the companion TA-windows-firewall-posture - the current configuration state of every host. Built for Dashboard Studio 10.4: tabbed dashboards, network graphs for east-west and beaconing maps, timelines, trellis small multiples and conditional sections. Ships hardened data inputs, a version-tolerant field extraction, CIM compliant knowledge objects for the Network Traffic and Change data models, an accelerable data model, nine dashboards and twenty-four detections and reports.Built by Amara Mohamed Traore
splunk product badge

Default Version 4.0.0

August 25, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4

CIM Version: 8.x, 6.x

Rating
5
(2)

Log in to rate this app

Support
Developer Supported

This App was designed to Collect, parse, normalise and visualise Windows Defender Firewall activity: the connection log (pfirewall.log), the configuration and policy change events, the Windows Filtering Platform audit events that attribute a connection to the binary that opened it, and - with the companion TA-windows-firewall-posture - the current configuration state of every host. Built for Dashboard Studio 10.4: tabbed dashboards, network graphs for east-west and beaconing maps, timelines, trellis small multiples and conditional sections. Ships hardened data inputs, a version-tolerant field extraction, CIM compliant knowledge objects for the Network Traffic and Change data models, an accelerable data model, nine dashboards and twenty-four detections and reports.