July 29, 2026
F5 XC Add-on
Parses F5 Distributed Cloud security and access logs delivered via HEC, mapping HTTP access, WAF, Bot Defense, and service-policy events to the Web and Intrusion Detection data models.Built by Waleed AbosreeSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1
CIM Version: 8.x, 6.x
Log in to rate this app
The F5 Distributed Cloud (XC) Add-on provides CIM-compliant parsing and field mapping for F5 Distributed Cloud security and access logs delivered to Splunk via HTTP Event Collector. The add-on normalizes four classes of F5 XC events: HTTP access logs, WAF signature and violation events, Bot Defense verdicts, and L7 service-policy enforcement actions. All events share the sourcetype f5:xc and are mapped to the Web and Intrusion Detection data models, enabling the data to populate Enterprise Security dashboards (Security Posture, Intrusion Center, Web) and any CIM-based content without per-customer SPL customization. Field mappings include authentication details, HTTP metadata, geographic context, threat indicators, and response actions, with coverage varying by event class as determined by the sec_event_type field.
Log in to report this app listing.