Question:

What is the main difference between the Iris Investigate API and the Iris Enrich API?

Answer:

What is the main difference between the Iris Investigate API and the Iris Enrich API?

The Iris Enrich API was developed to take advantage of the vast amount of data available in the Iris dataset and is typically implemented in a SIEM solution, such as Splunk , or a custom-built data analytics platform using open-source solutions like the ELK stack. As the primary use case is bulk data enrichment, it is therefore optimized for fast response and high volume lookups, therefore it does not offer most of the search parameters available in the Iris Investigate API. Instead it accepts a list of up to 100 comma separated domains in the domain parameter.

Still need help?
Contact Support
Support Categories