Skip to main content
F5 XC Add-on app icon

F5 XC Add-on

Parses F5 Distributed Cloud security and access logs delivered via HEC, mapping HTTP access, WAF, Bot Defense, and service-policy events to the Web and Intrusion Detection data models.Built by Waleed Abosree
splunk product badge

Default Version 1.2.0

July 29, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1

CIM Version: 8.x, 6.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The F5 Distributed Cloud (XC) Add-on provides CIM-compliant parsing and field mapping for F5 Distributed Cloud security and access logs delivered to Splunk via HTTP Event Collector. The add-on normalizes four classes of F5 XC events: HTTP access logs, WAF signature and violation events, Bot Defense verdicts, and L7 service-policy enforcement actions. All events share the sourcetype f5:xc and are mapped to the Web and Intrusion Detection data models, enabling the data to populate Enterprise Security dashboards (Security Posture, Intrusion Center, Web) and any CIM-based content without per-customer SPL customization. Field mappings include authentication details, HTTP metadata, geographic context, threat indicators, and response actions, with coverage varying by event class as determined by the sec_event_type field.