<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:s="http://dev.splunk.com/ns/rest">
  <title>Splunkbase Apps</title>
  <link href="http://www.splunkbase.com/api/apps/entries/"/>
  <updated>2010-09-02T23:05:58+00:00</updated>
  <id>http://www.splunkbase.com/api/apps/entries/?category=Business_Intelligence</id>
  <opensearch:totalResults>6</opensearch:totalResults>
  <opensearch:itemsPerPage>10</opensearch:itemsPerPage>
  <opensearch:startIndex>1</opensearch:startIndex>
  <entry>
    <title>IP2Location - GeoIP Lookups</title>
    <updated>2009-02-11T15:46:36+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/IP2Location+-+GeoIP+Lookups</id>
    <link href="http://www.splunkbase.com/api/apps/entries/IP2Location+-+GeoIP+Lookups" rel="alternate"/>
    <author>
      <name>rataide</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">1017</s:key>
        <s:key name="author">rataide</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2009-02-09T14:22:11+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-02-11T15:46:36+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/IP2Location+-+GeoIP+Lookups</s:key>
        <s:key name="latestVersion">1.2</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Search Commands</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/IP2Location+-+GeoIP+Lookups</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>Provide IP-to-location look up support via a free GeoIP API.&#13;
&#13;
Please see README for non-trivial installation instructions.&#13;
&#13;
Latest changes (See CHANGELOG for full details):&#13;
&#13;
    * Enhancement: Added a switch ["-nodns"|"nodns"] to disable name resolution.&#13;
    Usage: ....| geoip -nodns dest_ip &#13;
&#13;
    * Enhancement: Now only real RFC/1918 IPs will have the city populated with "RFC/1918" other IPs with no resolution revert to "Unknown"</summary>
    <category term="Analytics" label="Analytics"/>
    <category term="Network_Security" label="Network Security"/>
  </entry>
  <entry>
    <title>Splunk for IIS W3C extended</title>
    <updated>2008-12-16T00:07:43+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+for+IIS+W3C+extended</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+for+IIS+W3C+extended" rel="alternate"/>
    <author>
      <name>canuck</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">1893</s:key>
        <s:key name="author">canuck</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-12-16T00:07:43+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-12-16T00:07:43+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+for+IIS+W3C+extended</s:key>
        <s:key name="latestVersion">0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Reports</s:item>
            <s:item>Fields</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">1</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+for+IIS+W3C+extended</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>The Splunk for IIS W3C extended application adds several saved searches which can be used for reporting and alerts.  In the near future this application will also add several event types related to common IIS attacks.</summary>
    <category term="Microsoft_Internet_Information_Services_%5BIIS%5D" label="Microsoft Internet Information Services [IIS]"/>
    <category term="Web_Analytics" label="Web Analytics"/>
  </entry>
  <entry>
    <title>Script for database inputs</title>
    <updated>2008-10-23T23:50:16+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Script+for+database+inputs</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Script+for+database+inputs" rel="alternate"/>
    <author>
      <name>rcarney</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">3334</s:key>
        <s:key name="author">rcarney</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-10-23T23:50:16+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-10-23T23:50:16+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Script+for+database+inputs</s:key>
        <s:key name="latestVersion">0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Scripted Inputs</s:item>
            <s:item>Integration</s:item>
            <s:item>Inputs</s:item>
            <s:item>Custom Processing</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">3.5</s:key>
        <s:key name="ratingCount">4</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Script+for+database+inputs</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This script is designed to be used as a scripted input for data contained in&#13;
database tables. Plese refer to the Splunk Admin guide for more information on&#13;
configuring scripted inputs.&#13;
&#13;
The script has been successfully used in a number of deployments, and should&#13;
work with Oracle, MySQL, and sybase databases as-is. Other database types can&#13;
be added by installing the appropriate perl DBD module, and editing the script&#13;
to configure for the new dbtype.&#13;
&#13;
In this version, all of the SQL code has been abstracted from the script, and&#13;
all parameters including the query are passed as commandline arguments to the&#13;
script.</summary>
    <category term="Security" label="Security"/>
    <category term="Databases" label="Databases"/>
    <category term="Business_Intelligence" label="Business Intelligence"/>
    <category term="Compliance" label="Compliance"/>
    <category term="Operations" label="Operations"/>
  </entry>
  <entry>
    <title>Information Adder</title>
    <updated>2008-10-23T16:07:24+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Information+Adder</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Information+Adder" rel="alternate"/>
    <author>
      <name>rataide</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">250</s:key>
        <s:key name="author">rataide</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-10-16T23:27:50+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-10-23T16:07:24+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Information+Adder</s:key>
        <s:key name="latestVersion">1.2</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Search Commands</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Information+Adder</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This search script will add additional information from a CSV file to your events.&#13;
&#13;
Changelog:&#13;
v1.2 - Now includes basic error checking and additional fixes for malformed CSV files</summary>
    <category term="Analytics" label="Analytics"/>
  </entry>
  <entry>
    <title>Splunk Globe</title>
    <updated>2008-04-28T09:04:09+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+Globe</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+Globe" rel="alternate"/>
    <author>
      <name>kordless</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">2001</s:key>
        <s:key name="author">kordless</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-04-28T09:04:08+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-04-28T09:04:09+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+Globe</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Reports</s:item>
            <s:item>Clients</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+Globe</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>Splunk Globe uses the Poly9 FreeEarth plugin.  Splunk Globe queries a Splunk instance for the most recent IP addresses, then plots them on the globe.  Updates occur in near real-time.</summary>
    <category term="Analytics" label="Analytics"/>
  </entry>
  <entry>
    <title>Web access reports</title>
    <updated>2008-03-06T01:23:34+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Web+access+reports</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Web+access+reports" rel="alternate"/>
    <author>
      <name>ssorkin</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">8483</s:key>
        <s:key name="author">ssorkin</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2007-08-17T21:43:51+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-03-06T01:23:34+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Web+access+reports</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Reports</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">4.5</s:key>
        <s:key name="ratingCount">4</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Web+access+reports</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/Web+access+reports/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">120</s:key>
        <s:key name="screenshotOriginalHeight">75</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/Web+access+reports/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">640</s:key>
        <s:key name="screenshotHeight">400</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/Web+access+reports/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">117</s:key>
        <s:key name="thumbnailHeight">73</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>Provides saved web access reports that you can access when needed.</summary>
    <category term="NCSA_combined" label="NCSA combined"/>
    <category term="NCSA_combined_with_cookie" label="NCSA combined with cookie"/>
    <category term="NCSA_common" label="NCSA common"/>
    <category term="E-commerce" label="E-commerce"/>
  </entry>
</feed>
