Skip to main content
TA-osquery app icon

TA-osquery

A Splunk Technology Add-ON that ingests, parses, and CIM maps osquery host telemetry for use in Splunk security apps.Built by Rod Soto
splunk product badge

Default Version 1.0.4

March 19, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3

CIM Version: 4.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported
Ranking

#34 in SIEM

#41 in Endpoint

TA-osqueryv1 is a Splunk Technology Add-On that collects and normalizes host telemetry from osquery. It parses osquery's JSON log output, fixes timestamps, and maps process and file activity events to Splunk's CIM Endpoint data model - making the data immediately usable in Splunk ES and other security apps. No custom code - purely configuration-driven.