Skip to main content
Process-IT Add-on for Stormshield app icon

Process-IT Add-on for Stormshield

The Stormshield Add-on provides event breaking, field extraction, and Common Information Model (CIM) compliance for Stormshield firewall syslog data within Splunk and Splunk Enterprise Security.Built by Romain Caputi
splunk product badge

Default Version 1.6.9

September 24, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4

CIM Version: 8.x

Rating
5
(2)

Log in to rate this app

Support
Developer Supported

The Stormshield Add-on provides event breaking, field extraction, and Common Information Model (CIM) compliance for Stormshield firewall syslog data within Splunk. The add-on processes raw Stormshield syslog events and classifies them into typed sourcetypes based on log category, including filter, connection, web, authentication, system, plugin, intrusion detection, server, DHCP, VPN, FTP, POP3, SMTP, SSL, XVPN, PVM, and sandboxing events. Each classified event is mapped to the appropriate CIM data model, enabling normalized field names and accelerated security use cases across Network Traffic, Web, Authentication, Intrusion Detection, Network Sessions, Change, and Vulnerabilities domains. This allows direct use with Splunk Enterprise Security. The add-on is designed for deployment on heavy forwarders or indexers that receive syslog data directly from Stormshield firewalls.