<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:s="http://dev.splunk.com/ns/rest">
  <title>SplunkBase Applications</title>
  <link href="http://www.splunkbase.com/api/apps/entries/"/>
  <link href="http://www.splunkbase.com/api/apps/entries?category=Business_Intelligence&amp;splunk_version=3.4.0&amp;offset=10&amp;count=10" rel="next"/>
  <updated>2010-02-08T23:58:31+00:00</updated>
  <id>http://www.splunkbase.com/api/apps/entries/?category=Business_Intelligence</id>
  <opensearch:totalResults>11</opensearch:totalResults>
  <opensearch:itemsPerPage>10</opensearch:itemsPerPage>
  <opensearch:startIndex>1</opensearch:startIndex>
  <entry>
    <title>Splunk for IMAP</title>
    <updated>2009-11-17T01:32:28+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+for+IMAP</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+for+IMAP" rel="alternate"/>
    <author>
      <name>erik</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">3518</s:key>
        <s:key name="author">erik</s:key>
        <s:key name="contactEmail">erik@splunk.com</s:key>
        <s:key name="dateAddonCreated">2007-08-19T04:54:12+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-11-17T01:32:28+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+for+IMAP</s:key>
        <s:key name="latestVersion">1.20</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Scripted Inputs</s:item>
            <s:item>Inputs</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">5.0</s:key>
        <s:key name="ratingCount">3</s:key>
        <s:key name="bundle_count">0</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+for+IMAP</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/Splunk+for+IMAP/icon.jpg</s:key>
        <s:key name="iconWidth">41</s:key>
        <s:key name="iconHeight">33</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/Splunk+for+IMAP/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">129</s:key>
        <s:key name="screenshotOriginalHeight">88</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/Splunk+for+IMAP/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">129</s:key>
        <s:key name="screenshotHeight">88</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/Splunk+for+IMAP/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">107</s:key>
        <s:key name="thumbnailHeight">73</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This application will continually download mail from an imap account where it is indexed by a Splunk server. You can do cool things like see how often you get mail from someone, graph by size, time, etc.</summary>
    <category term="Mail" label="Mail"/>
    <category term="Business_Intelligence" label="Business Intelligence"/>
  </entry>
  <entry>
    <title>RSS Scripted Input</title>
    <updated>2009-10-15T21:15:05+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/RSS+Scripted+Input</id>
    <link href="http://www.splunkbase.com/api/apps/entries/RSS+Scripted+Input" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">209</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail">nimish@splunk.com</s:key>
        <s:key name="dateAddonCreated">2009-08-13T23:40:34+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-10-15T21:15:05+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/RSS+Scripted+Input</s:key>
        <s:key name="latestVersion">1.0.2</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Scripted Inputs</s:item>
            <s:item>Inputs</s:item>
            <s:item>Fields</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/RSS+Scripted+Input</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/RSS+Scripted+Input/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This is a simple application to take the content of any RSS feed and index&#13;
its metadata (date, title, link, and description) into Splunk. A scripted input calls rss.sh every 600&#13;
seconds, which in turn, calls the supplied Python program, rssfeed.py to&#13;
gather the rss feeds. RSS feeds are supplied via a file passed on the command&#13;
line. A sample file, feeds.txt, is provided for testing. This program uses the&#13;
open source feedparser from www.feedparser.org for its RSS parser.&#13;
&#13;
Installation:&#13;
&#13;
Gunzip and un tar the distirbution into $SPLUNK_HOME/etc/apps and read the README.txt</summary>
    <category term="Analytics" label="Analytics"/>
    <category term="XML" label="XML"/>
    <category term="Python" label="Python"/>
    <category term="HTML" label="HTML"/>
  </entry>
  <entry>
    <title>Web Services Stock Quote as Scripted Input</title>
    <updated>2009-10-10T20:54:29+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Web+Services+Stock+Quote+as+Scripted+Input</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Web+Services+Stock+Quote+as+Scripted+Input" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">300</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail">nimish@splunk.com</s:key>
        <s:key name="dateAddonCreated">2008-12-09T18:06:56+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-10-10T20:54:29+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Web+Services+Stock+Quote+as+Scripted+Input</s:key>
        <s:key name="latestVersion">1.1.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Scripted Inputs</s:item>
            <s:item>Fields</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Web+Services+Stock+Quote+as+Scripted+Input</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/Web+Services+Stock+Quote+as+Scripted+Input/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/Web+Services+Stock+Quote+as+Scripted+Input/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">400</s:key>
        <s:key name="screenshotOriginalHeight">320</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/Web+Services+Stock+Quote+as+Scripted+Input/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">400</s:key>
        <s:key name="screenshotHeight">320</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/Web+Services+Stock+Quote+as+Scripted+Input/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">91</s:key>
        <s:key name="thumbnailHeight">73</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This distribution calls a stock quote web service with a list of stock symbols&#13;
as input which is output to Splunk's indexer. The code makes use of the Apache&#13;
Axis client library to call a web service as a scripted input to retrieve&#13;
stock quote reports for stock symbols and use each response as an event&#13;
stored in XML format. It is used as a demonstration for using web services&#13;
as a scripted input. The work to call the web service for each stock symbol is \&#13;
done in the GatherStockQuote.java program. To install, use tar zxvf and place the stockquotes directory under SPLUNK_HOME/etc/apps/. Then read the README_StockQuote.txt for further configuration.&#13;
&#13;
You can use this to create your own time series data store for stock information and create reports. This ships with one field action to get detailed information on a symbol. (use xmlkv to extract the symbol field).</summary>
    <category term="Financial_Services" label="Financial Services"/>
    <category term="SOA_-_Middleware" label="SOA / Middleware"/>
  </entry>
  <entry>
    <title>IP2Location - GeoIP Lookups</title>
    <updated>2009-02-11T15:46:36+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/IP2Location+-+GeoIP+Lookups</id>
    <link href="http://www.splunkbase.com/api/apps/entries/IP2Location+-+GeoIP+Lookups" rel="alternate"/>
    <author>
      <name>rataide</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">1004</s:key>
        <s:key name="author">rataide</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2009-02-09T14:22:11+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-02-11T15:46:36+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/IP2Location+-+GeoIP+Lookups</s:key>
        <s:key name="latestVersion">1.2</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Search Commands</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/IP2Location+-+GeoIP+Lookups</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>Provide IP-to-location look up support via a free GeoIP API.&#13;
&#13;
Please see README for non-trivial installation instructions.&#13;
&#13;
Latest changes (See CHANGELOG for full details):&#13;
&#13;
    * Enhancement: Added a switch ["-nodns"|"nodns"] to disable name resolution.&#13;
    Usage: ....| geoip -nodns dest_ip &#13;
&#13;
    * Enhancement: Now only real RFC/1918 IPs will have the city populated with "RFC/1918" other IPs with no resolution revert to "Unknown"</summary>
    <category term="Analytics" label="Analytics"/>
    <category term="Network_Security" label="Network Security"/>
  </entry>
  <entry>
    <title>Splunk for IIS W3C extended</title>
    <updated>2008-12-16T00:07:43+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+for+IIS+W3C+extended</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+for+IIS+W3C+extended" rel="alternate"/>
    <author>
      <name>canuck</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">1806</s:key>
        <s:key name="author">canuck</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-12-16T00:07:43+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-12-16T00:07:43+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+for+IIS+W3C+extended</s:key>
        <s:key name="latestVersion">0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Reports</s:item>
            <s:item>Fields</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">1</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+for+IIS+W3C+extended</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>The Splunk for IIS W3C extended application adds several saved searches which can be used for reporting and alerts.  In the near future this application will also add several event types related to common IIS attacks.</summary>
    <category term="Microsoft_Internet_Information_Services_%5BIIS%5D" label="Microsoft Internet Information Services [IIS]"/>
    <category term="Web_Analytics" label="Web Analytics"/>
  </entry>
  <entry>
    <title>Script for database inputs</title>
    <updated>2008-10-23T23:50:16+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Script+for+database+inputs</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Script+for+database+inputs" rel="alternate"/>
    <author>
      <name>rcarney</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">3152</s:key>
        <s:key name="author">rcarney</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-10-23T23:50:16+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-10-23T23:50:16+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Script+for+database+inputs</s:key>
        <s:key name="latestVersion">0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Scripted Inputs</s:item>
            <s:item>Integration</s:item>
            <s:item>Inputs</s:item>
            <s:item>Custom Processing</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">3.5</s:key>
        <s:key name="ratingCount">4</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Script+for+database+inputs</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This script is designed to be used as a scripted input for data contained in&#13;
database tables. Plese refer to the Splunk Admin guide for more information on&#13;
configuring scripted inputs.&#13;
&#13;
The script has been successfully used in a number of deployments, and should&#13;
work with Oracle, MySQL, and sybase databases as-is. Other database types can&#13;
be added by installing the appropriate perl DBD module, and editing the script&#13;
to configure for the new dbtype.&#13;
&#13;
In this version, all of the SQL code has been abstracted from the script, and&#13;
all parameters including the query are passed as commandline arguments to the&#13;
script.</summary>
    <category term="Security" label="Security"/>
    <category term="Databases" label="Databases"/>
    <category term="Business_Intelligence" label="Business Intelligence"/>
    <category term="Compliance" label="Compliance"/>
    <category term="Operations" label="Operations"/>
  </entry>
  <entry>
    <title>Information Adder</title>
    <updated>2008-10-23T16:07:24+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Information+Adder</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Information+Adder" rel="alternate"/>
    <author>
      <name>rataide</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">247</s:key>
        <s:key name="author">rataide</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-10-16T23:27:50+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-10-23T16:07:24+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Information+Adder</s:key>
        <s:key name="latestVersion">1.2</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Search Commands</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Information+Adder</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This search script will add additional information from a CSV file to your events.&#13;
&#13;
Changelog:&#13;
v1.2 - Now includes basic error checking and additional fixes for malformed CSV files</summary>
    <category term="Analytics" label="Analytics"/>
  </entry>
  <entry>
    <title>Splunk License Usage</title>
    <updated>2008-06-23T15:55:31+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+License+Usage</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+License+Usage" rel="alternate"/>
    <author>
      <name>joshs</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">3092</s:key>
        <s:key name="author">joshs</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-06-03T22:18:58+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-06-23T15:55:31+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+License+Usage</s:key>
        <s:key name="latestVersion">1.2</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Reports</s:item>
            <s:item>Other</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">5.0</s:key>
        <s:key name="ratingCount">8</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+License+Usage</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This bundle provides a new dashboard which has several widgets that query to help you determine your Splunk license usage total over the past 24 hours as well as usage by host, source, and sourcetype. It contains timecharts to help you understand usage over time and see usage spikes as well as pie charts to help you to figure out which log files, sourcetypes, and hosts Splunk is indexing the most data from.</summary>
    <category term="Analytics" label="Analytics"/>
    <category term="Splunk" label="Splunk"/>
  </entry>
  <entry>
    <title>Splunk Globe</title>
    <updated>2008-04-28T09:04:09+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+Globe</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+Globe" rel="alternate"/>
    <author>
      <name>kordless</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">1988</s:key>
        <s:key name="author">kordless</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-04-28T09:04:08+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-04-28T09:04:09+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+Globe</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Reports</s:item>
            <s:item>Clients</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+Globe</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>Splunk Globe uses the Poly9 FreeEarth plugin.  Splunk Globe queries a Splunk instance for the most recent IP addresses, then plots them on the globe.  Updates occur in near real-time.</summary>
    <category term="Analytics" label="Analytics"/>
  </entry>
  <entry>
    <title>Splunk License Usage</title>
    <updated>2008-06-23T15:55:31+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+License+Usage</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+License+Usage" rel="alternate"/>
    <author>
      <name>joshs</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">3092</s:key>
        <s:key name="author">joshs</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-06-03T22:18:58+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-06-23T15:55:31+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+License+Usage</s:key>
        <s:key name="latestVersion">1.2</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Reports</s:item>
            <s:item>Other</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">5.0</s:key>
        <s:key name="ratingCount">8</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+License+Usage</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This bundle provides a new dashboard which has several widgets that query to help you determine your Splunk license usage total over the past 24 hours as well as usage by host, source, and sourcetype. It contains timecharts to help you understand usage over time and see usage spikes as well as pie charts to help you to figure out which log files, sourcetypes, and hosts Splunk is indexing the most data from.</summary>
    <category term="Analytics" label="Analytics"/>
    <category term="Splunk" label="Splunk"/>
  </entry>
</feed>
