Default Version 1.0.3
August 25, 2026
August 25, 2026
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
Log in to rate this app
Events collected from pfirewall.log and Windows Event Log cannot tell you the current STATE. If a host had its firewall turned off before you deployed Splunk, no change event will ever be produced and the host simply looks quiet. Worse: a host with "Log dropped packets" disabled produces no traffic log at all, and is indistinguishable from a host with no network activity. This add-on closes that gap by inventorying the configuration itself.
Log in to report this app listing.