Skip to main content
PT NAD app icon

PT NAD

Official Positive Technologies add-on for ingesting, parsing, CIM-normalizing, and visualizing PT NAD JSON syslog events in Splunk Enterprise, including attacks, activities, IoCs, audit events, and combined multi-rule incidents.Built by Sina Mohebi
splunk product badge

Default Version 1.4.1

August 8, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 8.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The Official PT NAD Add-on for Splunk enables organizations to ingest, parse, normalize, search, and visualize JSON syslog events generated by Positive Technologies Network Attack Discovery (PT NAD). The add-on addresses the need to integrate PT NAD telemetry with Splunk Enterprise without requiring administrators to create custom field extractions for every event type. It supports attack alerts, activity detections, indicators of compromise, audit events, and combined incidents containing multiple detection rules. PT NAD fields are normalized for the Splunk Common Information Model (CIM), including the Intrusion Detection, Alerts, Authentication, and Change data models. The add-on also provides event types, CIM tags, historical-event parsing, normalized correlation identifiers, multi-rule incident fields, and the PT NAD Security Overview dashboard. This add-on prepares PT NAD data for customer-developed correlation searches and detection content. It does not synchronize PT NAD asset discovery with the Splunk Enterprise Security Asset and Identity Framework, create customer-specific correlation searches, or install automated response playbooks.