The Appgate SDP Add-on provides CIM-compliant field extractions, eventtypes, and tags for Appgate SDP (Software Defined Perimeter / Zero Trust Network Access) audit events. The add-on processes single-line JSON-formatted events from the appgate:sdp sourcetype and maps them to five CIM data models: Network Traffic, Authentication, Network Sessions, Certificates, and Compute Inventory. All field mappings are applied at search time using KV_MODE=json, field aliases, calculated fields, lookups, eventtypes, and tags. The add-on supports events ingested through SC4S to HEC as well as alternative paths including file monitor, TCP, and Universal Forwarder. It expects events in a structured JSON envelope format with a nested log payload. The CIM mappings have been verified against CIM 8.5 data model documentation and align with the Appgate SDP v6.4 audit log catalog. This add-on establishes the canonical sourcetype convention for Appgate SDP events in Splunk deployments.