Home
Join the Community
Welcome Center
Welcome Center
Join Slack
Be a Splunk Champion
SplunkTrust
Splunk MVP
Become a User Group Leader
Splunk Love
Share a Tip
Find Answers
Splunk Administration
Getting Data In
Deployment Architecture
Monitoring Splunk
Using Splunk
Splunk Search
Dashboards & Visualizations
Splunk Products
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud Platform
Splunk Observability Cloud
Splunk AppDynamics
Splunk SOAR
Apps & Add-ons
All Apps and Add-ons
Splunk Development
Events
User Groups
Tech Talks: Technical Deep Dives
Office Hours: Ask the Experts
From Data to Insight: The Splunk Dashboard Contest
Dashboard Contest Terms and Conditions
Blogs
Community Blog
Product News & Announcements
Training & Certification Blog
Learning
Learning Paths
Training & Certification
Training + Certification Discussions
AppDynamics Knowledge Base
Best of conf
Resources
.conf25
Splunkbase
Developers
Documentation
Splunk Ideas
Splunk Events
Voice of Customer
Sign In
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for
Show
only
|
Search instead for
Did you mean:
Aviatrix Security
Splunk Community
×
Join the Conversation
Without signing in, you're just watching from the sidelines.
Sign in or Register
to connect, share, and be part of the Splunk Community.
Ask a Question
Aviatrix Security
Options
Subscribe
Aviatrix Security
Aviatrix Security
Security visibility and analytics for Aviatrix Distributed Cloud Firewall in Splunk. Provides CIM-compliant field extractions and six pre-built dashboards for SIEM/SOC teams monitoring multi-cloud network security. Dashboards included: - Security Overview: Executive security posture with KPIs, threat timeline, top blocked destinations, and gateway block rates - Traffic Analysis: L4/L7/FQDN traffic patterns, top sources/destinations, and protocol breakdown - Threat Detection: IDS alert severity, Suricata signature analysis, and source/destination correlation - Policy Enforcement: L7 policy hits, allow/deny ratios, and domain analysis - Gateway Health: CPU, memory, disk, and network throughput monitoring per gateway - Audit Trail: Controller API changes, user activity, and success/failure tracking Supported log types: - Aviatrix Cloud Firewall L4 micro-segmentation logs - Aviatrix Cloud Firewall L7 TLS/SNI inspection logs - Aviatrix Cloud Firewall IDS alerts (EVE JSON) - Gateway network and system statistics - Cloud Native Security Fabric API audit logs CIM data models supported: Network Traffic, Intrusion Detection, Change Analysis Requires the companion TA-aviatrix add-on for field extractions and CIM compliance. Logs are ingested via the Aviatrix SIEM Connector using Splunk HEC (HTTP Event Collector).
Ask a Question
View in Splunkbase
0
topics and
0
replies mentioned Aviatrix Security in
Splunk Community
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.