The Analyst1 App for Splunk is an add-on designed for use by existing Analyst1 customers.
Built by
Latest Version 1.5.5
September 23, 2025
Compatibility
This is compatibility for the latest version
Not Available
Platform Version: 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
Rating
0
(0)
Log in to rate this app
Support
Developer Supported addon
Ranking
#31
in Threat Intel
The Analyst1 App for Splunk is an add-on designed for use by existing Analyst1 customers.
This add-on has two main functions:
1. Brings enrichment data around observables/indicators of compromise from Analyst1 into Splunk, providing lookup tables for correlation data.
2. Sends network/host log data from Splunk to Analyst1, correlating syslogs into hits against IOCs