Skip to main content
Xage Add-on for Splunk app icon

Xage Add-on for Splunk

Technical add-on to parse Xage Fabric syslog audit logs and normalize them to Splunk CIM (Authentication, Change, Alerts).Built by Ron Conant
splunk product badge

Default Version 1.3.5

September 17, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 8.x, 6.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The Xage Fabric TA is a technical add-on that ingests and normalizes Xage Fabric syslog audit logs into Splunk's Common Information Model. The add-on parses RFC5424-formatted syslog messages containing JSON audit payloads, extracting authentication events, configuration changes, and security alerts. Events are automatically tagged and mapped to the CIM Authentication, Change, and Alerts data models. The add-on handles both TCP and UDP syslog inputs as well as file-based monitoring, and performs sourcetype classification at index time to ensure proper field extraction. It is designed to operate in conjunction with the companion stg_Xage app, which provides visualization dashboards and Enterprise Security correlation searches. The add-on provides field extractions, event type definitions, and CIM tags but does not include user-facing dashboards or saved searches.