Skip to main content
Add-on for windows firewall posture app icon

Add-on for windows firewall posture

This add-on additionally collects the default actions, the logging configuration, the log file health and the rule inventoryBuilt by Amara Mohamed Traore
splunk product badge

Default Version 1.0.3

August 25, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

Events collected from pfirewall.log and Windows Event Log cannot tell you the current STATE. If a host had its firewall turned off before you deployed Splunk, no change event will ever be produced and the host simply looks quiet. Worse: a host with "Log dropped packets" disabled produces no traffic log at all, and is indistinguishable from a host with no network activity. This add-on closes that gap by inventorying the configuration itself.