Skip to main content
TA Zeek JSON Parsing app icon

TA Zeek JSON Parsing

Splunk Technology Add-on that splits newline-delimited Zeek JSON logs into individual events, extracts the fields, uses the Zeek ts field as event time, and sets the zeek_json sourcetype automatically.Built by Kaled Aljebur
splunk product badge

Default Version 1.4.0

September 21, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

Zeek JSON logs are often indexed as one grouped event. This add-on splits every JSON line into its own event, extracts the fields, uses the Zeek "ts" field as event time, and sets the sourcetype zeek_json automatically for common Zeek log names, in any folder. No sourcetype needs to be set on the input. Deploy on the parsing tier (heavy forwarder or indexer).