SplunkIOC EnrichmentCustom Search Command+3
DFIR Platform + Splunk: IOC Enrichment via Custom Search Commands
Build a Splunk custom search command that enriches IOCs via DFIR Platform API. Includes Python code, commands.conf configuration, packaging as a Splunk app, and example SPL queries.
Apr 14, 202611 min read