July 15, 2026
NuHarbor - TA for AppGate Zero Trust Network Access
Provides CIM-compliant field extractions and mappings for Appgate SDP audit events across Network Traffic, Authentication, Network Sessions, Certificates, and Compute Inventory data models.Built by Paul KiripolskySplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 8.x, 6.x
Log in to rate this app
The Appgate SDP Add-on provides CIM-compliant field extractions, eventtypes, and tags for Appgate SDP (Software Defined Perimeter / Zero Trust Network Access) audit events. The add-on processes single-line JSON-formatted events from the appgate:sdp sourcetype and maps them to five CIM data models: Network Traffic, Authentication, Network Sessions, Certificates, and Compute Inventory. All field mappings are applied at search time using KV_MODE=json, field aliases, calculated fields, lookups, eventtypes, and tags. The add-on supports events ingested through SC4S to HEC as well as alternative paths including file monitor, TCP, and Universal Forwarder. It expects events in a structured JSON envelope format with a nested log payload. The CIM mappings have been verified against CIM 8.5 data model documentation and align with the Appgate SDP v6.4 audit log catalog. This add-on establishes the canonical sourcetype convention for Appgate SDP events in Splunk deployments.
Log in to report this app listing.