The Zyxel Add-on for Splunk Enterprise (TA_Zyxel_Splunk) sets the correct sourcetype, fields used for identifying data from Zyxel firewall using Splunk® Enterprise & Splunk® Cloud for all the categories of logs. This also allows Splunk software administrators to map Zyxel firewall device events to the Splunk CIM.
Install this Add-On on your Heavy forwarder indexer and search head. Install the Zyxel firewall Splunk App (Avo_Zyxel_Firewall_Monitor) on your search head and get an insight into firewall data via dashboards, data models, reports, alerts, and security use cases.