Default Version 1.0.0
September 7, 2025
September 7, 2025
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 6.x
Log in to rate this app
This Technology Add-on (TA) provides field extractions, event types, tags, and lookups to normalize Security Onion Zeek and Suricata logs into Splunk Common Information Model (CIM). It enables better visibility into network security events and integrates seamlessly with Splunk Enterprise Security.
Log in to report this app listing.