Skip to main content
NuHarbor - TA for AppGate Zero Trust Network Access app icon

NuHarbor - TA for AppGate Zero Trust Network Access

Provides CIM-compliant field extractions and mappings for Appgate SDP audit events across Network Traffic, Authentication, Network Sessions, Certificates, and Compute Inventory data models.Built by Paul Kiripolsky
splunk product badge

Default Version 1.1.1

July 15, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 8.x, 6.x

Rating
5
(1)

Log in to rate this app

Support
Developer Supported

The Appgate SDP Add-on provides CIM-compliant field extractions, eventtypes, and tags for Appgate SDP (Software Defined Perimeter / Zero Trust Network Access) audit events. The add-on processes single-line JSON-formatted events from the appgate:sdp sourcetype and maps them to five CIM data models: Network Traffic, Authentication, Network Sessions, Certificates, and Compute Inventory. All field mappings are applied at search time using KV_MODE=json, field aliases, calculated fields, lookups, eventtypes, and tags. The add-on supports events ingested through SC4S to HEC as well as alternative paths including file monitor, TCP, and Universal Forwarder. It expects events in a structured JSON envelope format with a nested log payload. The CIM mappings have been verified against CIM 8.5 data model documentation and align with the Appgate SDP v6.4 audit log catalog. This add-on establishes the canonical sourcetype convention for Appgate SDP events in Splunk deployments.