TA-osqueryv1 is a Splunk Technology Add-On that collects and normalizes host telemetry from osquery. It parses osquery's JSON log output, fixes timestamps, and maps process and file activity events to Splunk's CIM Endpoint data model - making the data immediately usable in Splunk ES and other security apps. No custom code - purely configuration-driven.