Default Version 1.4.0
September 21, 2026
September 21, 2026
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1
Log in to rate this app
Zeek JSON logs are often indexed as one grouped event. This add-on splits every JSON line into its own event, extracts the fields, uses the Zeek "ts" field as event time, and sets the sourcetype zeek_json automatically for common Zeek log names, in any folder. No sourcetype needs to be set on the input. Deploy on the parsing tier (heavy forwarder or indexer).
Log in to report this app listing.