September 17, 2026
Xage Add-on for Splunk
Technical add-on to parse Xage Fabric syslog audit logs and normalize them to Splunk CIM (Authentication, Change, Alerts).Built by Ron ConantSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 8.x, 6.x
Log in to rate this app
The Xage Fabric TA is a technical add-on that ingests and normalizes Xage Fabric syslog audit logs into Splunk's Common Information Model. The add-on parses RFC5424-formatted syslog messages containing JSON audit payloads, extracting authentication events, configuration changes, and security alerts. Events are automatically tagged and mapped to the CIM Authentication, Change, and Alerts data models. The add-on handles both TCP and UDP syslog inputs as well as file-based monitoring, and performs sourcetype classification at index time to ensure proper field extraction. It is designed to operate in conjunction with the companion stg_Xage app, which provides visualization dashboards and Enterprise Security correlation searches. The add-on provides field extractions, event type definitions, and CIM tags but does not include user-facing dashboards or saved searches.
Log in to report this app listing.