September 24, 2026
Process-IT Add-on for Stormshield
The Stormshield Add-on provides event breaking, field extraction, and Common Information Model (CIM) compliance for Stormshield firewall syslog data within Splunk and Splunk Enterprise Security.Built by Romain CaputiSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4
CIM Version: 8.x
Log in to rate this app
The Stormshield Add-on provides event breaking, field extraction, and Common Information Model (CIM) compliance for Stormshield firewall syslog data within Splunk. The add-on processes raw Stormshield syslog events and classifies them into typed sourcetypes based on log category, including filter, connection, web, authentication, system, plugin, intrusion detection, server, DHCP, VPN, FTP, POP3, SMTP, SSL, XVPN, PVM, and sandboxing events. Each classified event is mapped to the appropriate CIM data model, enabling normalized field names and accelerated security use cases across Network Traffic, Web, Authentication, Intrusion Detection, Network Sessions, Change, and Vulnerabilities domains. This allows direct use with Splunk Enterprise Security. The add-on is designed for deployment on heavy forwarders or indexers that receive syslog data directly from Stormshield firewalls.
Log in to report this app listing.