The Analyst1 App for Splunk is an add-on designed for use by existing Analyst1 customers.
This add-on has two main functions:
1. Brings enrichment data around observables/indicators of compromise from Analyst1 into Splunk, providing lookup tables for correlation data.
2. Sends network/host log data from Splunk to Analyst1, correlating syslogs into hits against IOCs