This Splunk app will connect to a NetWitness Concentrator/Broker via REST API. It will poll the NetWitness device regularly to collect new session meta data based on the provided query to be indexed by Splunk, it tries to use the Common Information Model for most of the fields.
For install and configuration instructions please check README.txt after extracting it to $SPLUNK_HOME/etc/apps/