<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:s="http://dev.splunk.com/ns/rest">
  <title>SplunkBase Applications</title>
  <link href="http://www.splunkbase.com/api/apps/entries/"/>
  <updated>2010-02-09T12:45:37+00:00</updated>
  <id>http://www.splunkbase.com/api/apps/entries/?category=Compliance</id>
  <opensearch:totalResults>5</opensearch:totalResults>
  <opensearch:itemsPerPage>10</opensearch:itemsPerPage>
  <opensearch:startIndex>1</opensearch:startIndex>
  <entry>
    <title>Encrypt and Decrypt data within Events</title>
    <updated>2009-10-15T21:35:43+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Encrypt+and+Decrypt+data+within+Events</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Encrypt+and+Decrypt+data+within+Events" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">111</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail">nimish@splunk.com</s:key>
        <s:key name="dateAddonCreated">2009-10-07T17:23:55+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-10-15T21:35:43+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Encrypt+and+Decrypt+data+within+Events</s:key>
        <s:key name="latestVersion">1.0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Search Commands</s:item>
            <s:item>Inputs</s:item>
            <s:item>Custom Processing</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">1</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Encrypt+and+Decrypt+data+within+Events</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/Encrypt+and+Decrypt+data+within+Events/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>The purpose of this distribution is to create an easy way to encrypt data&#13;
within events and decrypt data at search time depending on the role. The&#13;
distribution uses pyDes available at http://twhiteman.netfirms.com/des.html&#13;
&#13;
The basic idea is to first encrypt data within an event and produce a new file&#13;
with the same content as before, but with the data matching group(1) in a&#13;
regular expression encrypted and saved on disk using base64. The next thing&#13;
to do is index the newly required file into Splunk with a sourcetype.&#13;
&#13;
At search time, you will then be able to decrypt the data within the event&#13;
based on your role's ability to run the supplied decrypt command. Read the README.txt for installation and usage.</summary>
    <category term="Data_Security" label="Data Security"/>
    <category term="Misuse" label="Misuse"/>
    <category term="Content_Security" label="Content Security"/>
    <category term="Regulations" label="Regulations"/>
  </entry>
  <entry>
    <title>Splunk for OSSEC</title>
    <updated>2009-06-17T21:19:00+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+for+OSSEC</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+for+OSSEC" rel="alternate"/>
    <author>
      <name>elazar</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">1988</s:key>
        <s:key name="author">elazar</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2009-02-16T18:24:43+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-06-17T21:19:00+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+for+OSSEC</s:key>
        <s:key name="latestVersion">0.4.3</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Fields</s:item>
            <s:item>Event Types</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">4.0</s:key>
        <s:key name="ratingCount">6</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+for+OSSEC</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/Splunk+for+OSSEC/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">191</s:key>
        <s:key name="screenshotOriginalHeight">81</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/Splunk+for+OSSEC/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">640</s:key>
        <s:key name="screenshotHeight">271</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/Splunk+for+OSSEC/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">118</s:key>
        <s:key name="thumbnailHeight">50</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>Field extraction for OSSEC HIDS(http://www.ossec.net)</summary>
    <category term="Compliance" label="Compliance"/>
    <category term="OSSEC" label="OSSEC"/>
    <category term="Network_Security" label="Network Security"/>
  </entry>
  <entry>
    <title>Splunk for PCI for Splunk 3.x</title>
    <updated>2009-03-23T23:06:28+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+for+PCI+for+Splunk+3.x</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+for+PCI+for+Splunk+3.x" rel="alternate"/>
    <author>
      <name>Splunk</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">5031</s:key>
        <s:key name="author">Splunk</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-01-11T00:03:07+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-03-23T23:06:28+00:00</s:key>
        <s:key name="price">Email sales@splunk.com for pricing</s:key>
        <s:key name="license">Contact Splunk For Trial</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+for+PCI+for+Splunk+3.x</s:key>
        <s:key name="latestVersion">for Splunk 3.3 and 3.4</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Reports</s:item>
            <s:item>Event Types</s:item>
            <s:item>Alerts</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">4.5</s:key>
        <s:key name="ratingCount">6</s:key>
        <s:key name="bundle_count">0</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+for+PCI+for+Splunk+3.x</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/Splunk+for+PCI+for+Splunk+3.x/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">120</s:key>
        <s:key name="screenshotOriginalHeight">75</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/Splunk+for+PCI+for+Splunk+3.x/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">640</s:key>
        <s:key name="screenshotHeight">400</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/Splunk+for+PCI+for+Splunk+3.x/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">117</s:key>
        <s:key name="thumbnailHeight">73</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>The Splunk PCI application offers over 57 reports, more than 91 saved searches, a dashboard, and corresponding alerts you can use to satisfy PCI requirements such as secure remote access, file integrity monitoring, secure log collection, daily log review, audit trail retention, and PCI control reporting.</summary>
    <category term="PCI" label="PCI"/>
  </entry>
  <entry>
    <title>Script for database inputs</title>
    <updated>2008-10-23T23:50:16+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Script+for+database+inputs</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Script+for+database+inputs" rel="alternate"/>
    <author>
      <name>rcarney</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">3152</s:key>
        <s:key name="author">rcarney</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-10-23T23:50:16+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-10-23T23:50:16+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Script+for+database+inputs</s:key>
        <s:key name="latestVersion">0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Scripted Inputs</s:item>
            <s:item>Integration</s:item>
            <s:item>Inputs</s:item>
            <s:item>Custom Processing</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">3.5</s:key>
        <s:key name="ratingCount">4</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Script+for+database+inputs</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This script is designed to be used as a scripted input for data contained in&#13;
database tables. Plese refer to the Splunk Admin guide for more information on&#13;
configuring scripted inputs.&#13;
&#13;
The script has been successfully used in a number of deployments, and should&#13;
work with Oracle, MySQL, and sybase databases as-is. Other database types can&#13;
be added by installing the appropriate perl DBD module, and editing the script&#13;
to configure for the new dbtype.&#13;
&#13;
In this version, all of the SQL code has been abstracted from the script, and&#13;
all parameters including the query are passed as commandline arguments to the&#13;
script.</summary>
    <category term="Security" label="Security"/>
    <category term="Databases" label="Databases"/>
    <category term="Business_Intelligence" label="Business Intelligence"/>
    <category term="Compliance" label="Compliance"/>
    <category term="Operations" label="Operations"/>
  </entry>
  <entry>
    <title>Negative Searching Demo Bundle</title>
    <updated>2007-09-07T04:18:53+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Negative+Searching+Demo+Bundle</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Negative+Searching+Demo+Bundle" rel="alternate"/>
    <author>
      <name>maverick</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">753</s:key>
        <s:key name="author">maverick</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2007-08-13T04:17:04+00:00</s:key>
        <s:key name="dateAddonUpdated">2007-09-07T04:18:53+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Negative+Searching+Demo+Bundle</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Reports</s:item>
            <s:item>Inputs</s:item>
            <s:item>Fields</s:item>
            <s:item>Alerts</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">1</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Negative+Searching+Demo+Bundle</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This bundle, created jointly by Maverick and Stephen Sorkin, demonstrates a way to perform negative searches by indexing known patterns and catching anomalous patterns into a separate index.</summary>
    <category term="Compliance" label="Compliance"/>
  </entry>
</feed>
