<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:s="http://dev.splunk.com/ns/rest">
  <title>Splunkbase Apps</title>
  <link href="http://www.splunkbase.com/api/apps/entries/"/>
  <updated>2010-09-02T23:06:11+00:00</updated>
  <id>http://www.splunkbase.com/api/apps/entries/?category=Compliance</id>
  <opensearch:totalResults>4</opensearch:totalResults>
  <opensearch:itemsPerPage>10</opensearch:itemsPerPage>
  <opensearch:startIndex>1</opensearch:startIndex>
  <entry>
    <title>Splunk for OSSEC</title>
    <updated>2009-06-17T21:19:00+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+for+OSSEC</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+for+OSSEC" rel="alternate"/>
    <author>
      <name>elazar</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">2198</s:key>
        <s:key name="author">elazar</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2009-02-16T18:24:43+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-06-17T21:19:00+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+for+OSSEC</s:key>
        <s:key name="latestVersion">0.4.3</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Fields</s:item>
            <s:item>Event Types</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">4.0</s:key>
        <s:key name="ratingCount">6</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+for+OSSEC</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/Splunk+for+OSSEC/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">191</s:key>
        <s:key name="screenshotOriginalHeight">81</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/Splunk+for+OSSEC/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">640</s:key>
        <s:key name="screenshotHeight">271</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/Splunk+for+OSSEC/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">118</s:key>
        <s:key name="thumbnailHeight">50</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>Field extraction for OSSEC HIDS(http://www.ossec.net)</summary>
    <category term="Compliance" label="Compliance"/>
    <category term="OSSEC" label="OSSEC"/>
    <category term="Network_Security" label="Network Security"/>
  </entry>
  <entry>
    <title>Splunk for PCI for Splunk 3.x</title>
    <updated>2009-03-23T23:06:28+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+for+PCI+for+Splunk+3.x</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+for+PCI+for+Splunk+3.x" rel="alternate"/>
    <author>
      <name>Splunk</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">5031</s:key>
        <s:key name="author">Splunk</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-01-11T00:03:07+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-03-23T23:06:28+00:00</s:key>
        <s:key name="price">Email sales@splunk.com for pricing</s:key>
        <s:key name="license">Contact Splunk For Trial</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+for+PCI+for+Splunk+3.x</s:key>
        <s:key name="latestVersion">for Splunk 3.3 and 3.4</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Reports</s:item>
            <s:item>Event Types</s:item>
            <s:item>Alerts</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">4.5</s:key>
        <s:key name="ratingCount">6</s:key>
        <s:key name="bundle_count">0</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+for+PCI+for+Splunk+3.x</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/Splunk+for+PCI+for+Splunk+3.x/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">120</s:key>
        <s:key name="screenshotOriginalHeight">75</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/Splunk+for+PCI+for+Splunk+3.x/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">640</s:key>
        <s:key name="screenshotHeight">400</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/Splunk+for+PCI+for+Splunk+3.x/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">117</s:key>
        <s:key name="thumbnailHeight">73</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>The Splunk PCI application offers over 57 reports, more than 91 saved searches, a dashboard, and corresponding alerts you can use to satisfy PCI requirements such as secure remote access, file integrity monitoring, secure log collection, daily log review, audit trail retention, and PCI control reporting.</summary>
    <category term="PCI" label="PCI"/>
  </entry>
  <entry>
    <title>Script for database inputs</title>
    <updated>2008-10-23T23:50:16+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Script+for+database+inputs</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Script+for+database+inputs" rel="alternate"/>
    <author>
      <name>rcarney</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">3334</s:key>
        <s:key name="author">rcarney</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-10-23T23:50:16+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-10-23T23:50:16+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Script+for+database+inputs</s:key>
        <s:key name="latestVersion">0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Scripted Inputs</s:item>
            <s:item>Integration</s:item>
            <s:item>Inputs</s:item>
            <s:item>Custom Processing</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">3.5</s:key>
        <s:key name="ratingCount">4</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Script+for+database+inputs</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This script is designed to be used as a scripted input for data contained in&#13;
database tables. Plese refer to the Splunk Admin guide for more information on&#13;
configuring scripted inputs.&#13;
&#13;
The script has been successfully used in a number of deployments, and should&#13;
work with Oracle, MySQL, and sybase databases as-is. Other database types can&#13;
be added by installing the appropriate perl DBD module, and editing the script&#13;
to configure for the new dbtype.&#13;
&#13;
In this version, all of the SQL code has been abstracted from the script, and&#13;
all parameters including the query are passed as commandline arguments to the&#13;
script.</summary>
    <category term="Security" label="Security"/>
    <category term="Databases" label="Databases"/>
    <category term="Business_Intelligence" label="Business Intelligence"/>
    <category term="Compliance" label="Compliance"/>
    <category term="Operations" label="Operations"/>
  </entry>
  <entry>
    <title>Negative Searching Demo Bundle</title>
    <updated>2007-09-07T04:18:53+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Negative+Searching+Demo+Bundle</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Negative+Searching+Demo+Bundle" rel="alternate"/>
    <author>
      <name>maverick</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">756</s:key>
        <s:key name="author">maverick</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2007-08-13T04:17:04+00:00</s:key>
        <s:key name="dateAddonUpdated">2007-09-07T04:18:53+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Negative+Searching+Demo+Bundle</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Reports</s:item>
            <s:item>Inputs</s:item>
            <s:item>Fields</s:item>
            <s:item>Alerts</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">1</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Negative+Searching+Demo+Bundle</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This bundle, created jointly by Maverick and Stephen Sorkin, demonstrates a way to perform negative searches by indexing known patterns and catching anomalous patterns into a separate index.</summary>
    <category term="Compliance" label="Compliance"/>
  </entry>
</feed>
