SafelineApp For Splunk app icon

SafelineApp For Splunk

Parses Chaitin SafeLine WAF syslog data, maps events to Web, Network Traffic, Intrusion Detection, and Alerts CIM domains, and provides dashboards for threat hunting, compliance, and operational visibility.

Built by hadi tayanloo
splunk product badge

Latest Version 2.0.0
May 8, 2026
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0, 8.2, 8.1, 8.0
CIM Version: 8.x, 6.x
Rating

5

(1)

Log in to rate this app
Support
SafelineApp For Splunk support icon
Developer Supported app
Ranking

#42

in Firewall
The SafeLine WAF app parses JSON syslog output from Chaitin SafeLine Web Application Firewall deployments and maps events to the Splunk Common Information Model. The app extracts approximately 70 fields per event, including HTTP request and response headers, attack metadata, client IP addresses, and WAF rule actions. Events are normalized to the Web, Network Traffic, Intrusion Detection, and Alerts CIM data models. The app provides 10 operational dashboards covering real-time monitoring, attack analysis, IP reputation scoring, bot detection, TLS fingerprint analysis, cross-site comparison, and compliance reporting. Seven pre-configured saved searches enable automated alerting on critical attack patterns, high-volume attackers, multi-site threats, mitigation rate degradation, and traffic anomalies. Workflow actions embedded in search results allow analysts to pivot to related events, drill down by site or attack rule, and launch OSINT lookups against external threat intelligence platforms.

Categories

Security, Fraud & Compliance, Firewall

Created By

hadi tayanloo

Type

app

Downloads

5

Resources

Log in to report this app listing