Skip to main content
Analyst1 for Splunk SOAR app icon

Analyst1 for Splunk SOAR

Interact with the Analyst1 API to power SOAR workflows, including indicator lookups, evidence management, and other supported Analyst1 operations.Built by SOAR Community
soar product badge

Default Version 2.0.0

August 11, 2026

Compatibility

SOAR On-Prem, SOAR Cloud

Platform Version: 8.7, 8.6, 8.5, 8.4, 8.0, 7.2, 7.1, 7.0

Rating
0
(0)

Log in to rate this app

Support
Not Supported

Interact with the Analyst1 API to power SOAR workflows, including indicator lookups, evidence management, and other supported Analyst1 operations.

Supported actions

  • test connectivity: Test connectivity to the Analyst1 platform.
  • lookup domain: Check for the presence of a domain in the Analyst1 platform
  • lookup email: Check for the presence of an email in the Analyst1 platform
  • lookup hash: Check for the presence of a hash in the Analyst1 platform
  • lookup string: Check for the presence of a string in the Analyst1 platform
  • lookup ip: Check for the presence of an IP in the Analyst1 platform
  • lookup ipv6: Check for the presence of an IPv6 in the Analyst1 platform
  • lookup url: Check for the presence of a URL in the Analyst1 platform
  • lookup mutex: Check for the presence of a mutex in the Analyst1 platform
  • lookup http request: Check for the presence of an HTTP request in the Analyst1 platform
  • batch check: Check a batch of indicator values (type auto-detected) against the Analyst1 platform
  • get indicator by id: Fetch an indicator from the Analyst1 platform by its Analyst1 ID
  • get actor by id: Fetch an actor from the Analyst1 platform by its Analyst1 ID
  • get malware by id: Fetch a malware family from the Analyst1 platform by its Analyst1 ID
  • upload evidence file: Upload file from vault to Analyst1 as evidence file
  • check evidence status: Check the status of an evidence file upload
  • get evidence: Browse and fetch evidence resources.
  • get sensors: Browse and fetch sensors from the Analyst1 platform
  • get sensor taskings: Fetch the indicators and rules currently tasked to an Analyst1 sensor
  • get sensor config: Fetch an Analyst1 sensor's current configuration file and store it in the vault
  • get sensor diff: Fetch the tasking differences between an Analyst1 sensor config version and the latest version