Skip to main content
Vali Cyber ZeroLock App app icon

Vali Cyber ZeroLock App

Provides search-time parsing and CIM normalization for ZeroLock hypervisor runtime-security telemetry, mapping events to Authentication, Malware, Intrusion Detection, and Change data models.Built by Austin Gadient
splunk product badge

Default Version 1.0.0

July 9, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 8.x, 6.x, 5.x, 4.x, 3.x

Rating
5
(4)

Log in to rate this app

Support
Developer Supported

The Vali Cyber ZeroLock Add-on for Splunk provides search-time parsing and normalization for ZeroLock Management Console telemetry. ZeroLock delivers runtime security monitoring at the ESXi and Linux hypervisor layer, generating activity and alert data that this add-on maps to the Splunk Common Information Model. The add-on processes events delivered via HTTP Event Collector under the sourcetype valicyber:zerolock and normalizes them into four CIM data models: Authentication, Malware, Intrusion Detection, and Change. This normalization enables integration with Splunk Enterprise Security and other CIM-aware applications. The add-on does not collect data directly; it processes hypervisor security telemetry already forwarded by the ZeroLock Management Console's built-in Splunk activity forwarder.