Default Version 1.0.5
January 15, 2026
January 15, 2026
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 6.x, 5.x, 4.x, 3.x
Log in to rate this app
The LinkShadow NDR Syslog App provides seamless ingestion, parsing, and normalization of LinkShadow's Network Detection & Response (NDR) CEF syslog events into Splunk. This app addresses the common challenge of standardizing and extracting actionable fields from LinkShadow alerts, allowing security teams to quickly analyze alerts, monitor threats, and correlate events in real time.
Log in to report this app listing.