You send each Splunk event to the LLM and receive the following in return:
→ MITRE ATT&CK technical mapping (like T1059.001)
→ 1-10 severity score + label
→ 2-3 sentence AI analysis
→ Specific action recommendation to the SOC analyst
→ False positive probability + justification
→ Kill chain phase
→ Automatic IOC inference