Skip to main content
Aviatrix Security app icon

Aviatrix Security

Security visibility and analytics for Aviatrix Distributed Cloud Firewall. Six pre-built dashboards for traffic analysis, threat detection, policy enforcement, gateway health, and audit trail monitoring. CIM-compliant with Network Traffic, Intrusion Detection, and Change Analysis data models.Built by Chris McHenry
splunk product badge

Default Version 2.0.0

March 1, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 5.x, 4.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported
Ranking

#41 in Firewall

Security visibility and analytics for Aviatrix Distributed Cloud Firewall in Splunk. Provides CIM-compliant field extractions and six pre-built dashboards for SIEM/SOC teams monitoring multi-cloud network security. Dashboards included: - Security Overview: Executive security posture with KPIs, threat timeline, top blocked destinations, and gateway block rates - Traffic Analysis: L4/L7/FQDN traffic patterns, top sources/destinations, and protocol breakdown - Threat Detection: IDS alert severity, Suricata signature analysis, and source/destination correlation - Policy Enforcement: L7 policy hits, allow/deny ratios, and domain analysis - Gateway Health: CPU, memory, disk, and network throughput monitoring per gateway - Audit Trail: Controller API changes, user activity, and success/failure tracking Supported log types: - Aviatrix Cloud Firewall L4 micro-segmentation logs - Aviatrix Cloud Firewall L7 TLS/SNI inspection logs - Aviatrix Cloud Firewall IDS alerts (EVE JSON) - Gateway network and system statistics - Cloud Native Security Fabric API audit logs CIM data models supported: Network Traffic, Intrusion Detection, Change Analysis Requires the companion TA-aviatrix add-on for field extractions and CIM compliance. Logs are ingested via the Aviatrix SIEM Connector using Splunk HEC (HTTP Event Collector).