The ThreatConnect App for Splunk lets users configure indicator collections and data model searches, performs data model searches, and provides dashboards for analyzing data model search matches and indicator collections. Indicator Collections configured with the ThreatConnect App for Splunk are used by the TA ThreatConnect Threat Intel app.
Requires: https://splunkbase.splunk.com/app/6485