<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:s="http://dev.splunk.com/ns/rest">
  <title>SplunkBase Applications</title>
  <link href="http://www.splunkbase.com/api/apps/entries/"/>
  <link href="http://www.splunkbase.com/api/apps/entries?Custom_Processing&amp;splunk_version=3.4.0&amp;offset=10&amp;count=10" rel="next"/>
  <updated>2010-02-09T15:27:03+00:00</updated>
  <id>http://www.splunkbase.com/api/apps/entries/?type=Custom_Processing</id>
  <opensearch:totalResults>17</opensearch:totalResults>
  <opensearch:itemsPerPage>10</opensearch:itemsPerPage>
  <opensearch:startIndex>1</opensearch:startIndex>
  <entry>
    <title>JMS Receiver for Indexing</title>
    <updated>2010-02-03T23:21:08+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/JMS+Receiver+for+Indexing</id>
    <link href="http://www.splunkbase.com/api/apps/entries/JMS+Receiver+for+Indexing" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">2</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2010-02-03T23:21:07+00:00</s:key>
        <s:key name="dateAddonUpdated">2010-02-03T23:21:08+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/JMS+Receiver+for+Indexing</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Scripted Inputs</s:item>
            <s:item>Inputs</s:item>
            <s:item>Custom Processing</s:item>
            <s:item>Clients</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/JMS+Receiver+for+Indexing</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/JMS+Receiver+for+Indexing/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/JMS+Receiver+for+Indexing/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">170</s:key>
        <s:key name="screenshotOriginalHeight">113</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/JMS+Receiver+for+Indexing/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">170</s:key>
        <s:key name="screenshotHeight">113</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/JMS+Receiver+for+Indexing/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">110</s:key>
        <s:key name="thumbnailHeight">73</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This distribution is a working example for indexing messages that are sent to JMS Queues.&#13;
Although the example heavily relies on WebLogic Server 10.3, it could be modified to work with&#13;
any JMS provider. Messages are delivered to a JMS Queue and Splunk is configured to run&#13;
a scripted input once to call a JMS Queue consumer. Every message the consumer receives&#13;
will be sent to standard output to be indexed. Although the distribution has been built&#13;
on Windows, it should be able to run on any platform supported by Splunk and the JMS&#13;
provider. To begin with, gunzip and untar the distribution into&#13;
SPLUNK_HOME\etc\apps and follow the instructions in the README.txt</summary>
    <category term="Partial_J2EE-JPEE_Implementations" label="Partial J2EE/JPEE Implementations"/>
    <category term="J2EE-JPEE_Development_and_Management_Tools" label="J2EE/JPEE Development and Management Tools"/>
    <category term="IBM_MQSeries" label="IBM MQSeries"/>
    <category term="Networking" label="Networking"/>
  </entry>
  <entry>
    <title>Encrypt and Decrypt data within Events</title>
    <updated>2009-10-15T21:35:43+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Encrypt+and+Decrypt+data+within+Events</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Encrypt+and+Decrypt+data+within+Events" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">111</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail">nimish@splunk.com</s:key>
        <s:key name="dateAddonCreated">2009-10-07T17:23:55+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-10-15T21:35:43+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Encrypt+and+Decrypt+data+within+Events</s:key>
        <s:key name="latestVersion">1.0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Search Commands</s:item>
            <s:item>Inputs</s:item>
            <s:item>Custom Processing</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">1</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Encrypt+and+Decrypt+data+within+Events</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/Encrypt+and+Decrypt+data+within+Events/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>The purpose of this distribution is to create an easy way to encrypt data&#13;
within events and decrypt data at search time depending on the role. The&#13;
distribution uses pyDes available at http://twhiteman.netfirms.com/des.html&#13;
&#13;
The basic idea is to first encrypt data within an event and produce a new file&#13;
with the same content as before, but with the data matching group(1) in a&#13;
regular expression encrypted and saved on disk using base64. The next thing&#13;
to do is index the newly required file into Splunk with a sourcetype.&#13;
&#13;
At search time, you will then be able to decrypt the data within the event&#13;
based on your role's ability to run the supplied decrypt command. Read the README.txt for installation and usage.</summary>
    <category term="Data_Security" label="Data Security"/>
    <category term="Misuse" label="Misuse"/>
    <category term="Content_Security" label="Content Security"/>
    <category term="Regulations" label="Regulations"/>
  </entry>
  <entry>
    <title>Capture HTTP POST or GET Request Parameters</title>
    <updated>2009-10-15T21:10:36+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Capture+HTTP+POST+or+GET+Request+Parameters</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Capture+HTTP+POST+or+GET+Request+Parameters" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">1257</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail">nimish@splunk.com</s:key>
        <s:key name="dateAddonCreated">2009-02-18T23:39:11+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-10-15T21:10:36+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Capture+HTTP+POST+or+GET+Request+Parameters</s:key>
        <s:key name="latestVersion">1.1.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Integration</s:item>
            <s:item>Inputs</s:item>
            <s:item>Custom Processing</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Capture+HTTP+POST+or+GET+Request+Parameters</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/Capture+HTTP+POST+or+GET+Request+Parameters/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This application consists of a servlet that captures the POST and/or GET&#13;
parameters for any HTTP request and sends to standard output a set of&#13;
&lt;tag&gt;=&lt;value&gt; terms seen as an event in Splunk. Because tag=value are the&#13;
terms in the events, automatic field extraction for search and reports will&#13;
occur for these terms. The purpose of this boiler plate Java Servlet is to&#13;
serve as a parameter collector for HTTP POST and GET requests that can be&#13;
customized for deployment.&#13;
&#13;
The servlet developed here was tested on Apache Tomcat 6.x, although it should&#13;
work in any servlet container. To further solidify it's usage, the user&#13;
may want to investigate using log4j as the framework for log collection. In&#13;
the Tomcat implementation, the output is captured in a configurable log rotated&#13;
file to be monitored by Splunk.&#13;
&#13;
*** OPTIONAL ***&#13;
This version also includes a servlet that uses the log4j framework.&#13;
&#13;
tar -zxvf the distribution and read the README for installation notes.</summary>
    <category term="Web_Servers" label="Web Servers"/>
    <category term="Partial_J2EE-JPEE_Implementations" label="Partial J2EE/JPEE Implementations"/>
  </entry>
  <entry>
    <title>Use Python Mail for Scripted Alerts</title>
    <updated>2009-10-15T21:03:42+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Use+Python+Mail+for+Scripted+Alerts</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Use+Python+Mail+for+Scripted+Alerts" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">393</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail">nimish@splunk.com</s:key>
        <s:key name="dateAddonCreated">2009-03-03T20:10:07+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-10-15T21:03:42+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Use+Python+Mail+for+Scripted+Alerts</s:key>
        <s:key name="latestVersion">1.0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Custom Processing</s:item>
            <s:item>Alerts</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Use+Python+Mail+for+Scripted+Alerts</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/Use+Python+Mail+for+Scripted+Alerts/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This script runs as a scripted alert in Splunk to send mail to recipients&#13;
whenever the alert conditions are met. It is similar in concept to the Javamail application available on Splunkbase. It uses Python to send the message.&#13;
The intent is to provide a framework to control when email should be sent.&#13;
Currently, the script uses Daily, Weekday, and Weekend to control what days&#13;
the email alert should be sent. With this in mind the included Python program&#13;
can be modified to also include what hours of the day email should be sent.&#13;
&#13;
Installation:&#13;
&#13;
Use tar zxvf to uncompress and untar the distribution and read the README.txt.</summary>
    <category term="Mail" label="Mail"/>
    <category term="Python" label="Python"/>
  </entry>
  <entry>
    <title>Sendemail (Custom)</title>
    <updated>2009-01-27T23:11:25+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Sendemail+%28Custom%29</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Sendemail+%28Custom%29" rel="alternate"/>
    <author>
      <name>araitz</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">263</s:key>
        <s:key name="author">araitz</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2009-01-27T23:11:25+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-01-27T23:11:25+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Sendemail+%28Custom%29</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Search Commands</s:item>
            <s:item>Custom Processing</s:item>
            <s:item>Alerts</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">2</s:key>
        <s:key name="bundle_count">0</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Sendemail+%28Custom%29</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This custom sendemail allows email attributes (e.g. to, from, body, subject) on a per-alert basis.</summary>
    <category term="Mail" label="Mail"/>
    <category term="Splunk" label="Splunk"/>
  </entry>
  <entry>
    <title>Splunk for VMware ESX Management</title>
    <updated>2009-01-24T06:30:25+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+for+VMware+ESX+Management</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+for+VMware+ESX+Management" rel="alternate"/>
    <author>
      <name>erik</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">11220</s:key>
        <s:key name="author">erik</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-09-02T21:56:19+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-01-24T06:30:25+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+for+VMware+ESX+Management</s:key>
        <s:key name="latestVersion">1.20</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Scripted Inputs</s:item>
            <s:item>Event Types</s:item>
            <s:item>Custom Processing</s:item>
            <s:item>Alerts</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">4.0</s:key>
        <s:key name="ratingCount">13</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+for+VMware+ESX+Management</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/Splunk+for+VMware+ESX+Management/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">135</s:key>
        <s:key name="screenshotOriginalHeight">52</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/Splunk+for+VMware+ESX+Management/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">640</s:key>
        <s:key name="screenshotHeight">247</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/Splunk+for+VMware+ESX+Management/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">118</s:key>
        <s:key name="thumbnailHeight">45</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>Splunk indexes all IT data across every tier - the physical servers, hypervisor, VMs, and deployed applications, capturing and persisting 100% of your data in real-time. It includes inputs, indexing, searches, reports and dashboards.</summary>
    <category term="Virtualization" label="Virtualization"/>
    <category term="VMWare_Virtual_Center" label="VMWare Virtual Center"/>
    <category term="VMWare_ESX_Server" label="VMWare ESX Server"/>
  </entry>
  <entry>
    <title>Script for database inputs</title>
    <updated>2008-10-23T23:50:16+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Script+for+database+inputs</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Script+for+database+inputs" rel="alternate"/>
    <author>
      <name>rcarney</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">3152</s:key>
        <s:key name="author">rcarney</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-10-23T23:50:16+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-10-23T23:50:16+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Script+for+database+inputs</s:key>
        <s:key name="latestVersion">0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Scripted Inputs</s:item>
            <s:item>Integration</s:item>
            <s:item>Inputs</s:item>
            <s:item>Custom Processing</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">3.5</s:key>
        <s:key name="ratingCount">4</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Script+for+database+inputs</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This script is designed to be used as a scripted input for data contained in&#13;
database tables. Plese refer to the Splunk Admin guide for more information on&#13;
configuring scripted inputs.&#13;
&#13;
The script has been successfully used in a number of deployments, and should&#13;
work with Oracle, MySQL, and sybase databases as-is. Other database types can&#13;
be added by installing the appropriate perl DBD module, and editing the script&#13;
to configure for the new dbtype.&#13;
&#13;
In this version, all of the SQL code has been abstracted from the script, and&#13;
all parameters including the query are passed as commandline arguments to the&#13;
script.</summary>
    <category term="Security" label="Security"/>
    <category term="Databases" label="Databases"/>
    <category term="Business_Intelligence" label="Business Intelligence"/>
    <category term="Compliance" label="Compliance"/>
    <category term="Operations" label="Operations"/>
  </entry>
  <entry>
    <title>Consuming Splunk RSS Feeds in Java</title>
    <updated>2008-08-13T17:07:55+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Consuming+Splunk+RSS+Feeds+in+Java</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Consuming+Splunk+RSS+Feeds+in+Java" rel="alternate"/>
    <author>
      <name>nimishd</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">77</s:key>
        <s:key name="author">nimishd</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-08-13T17:07:55+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-08-13T17:07:55+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Consuming+Splunk+RSS+Feeds+in+Java</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Custom Processing</s:item>
            <s:item>Alerts</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">0</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Consuming+Splunk+RSS+Feeds+in+Java</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>This application demonstrates how to consume an RSS alert feed in Java from any&#13;
saved search from Splunk. It uses Sun's RSS parser (included) to gather the feed&#13;
and breaks up the fields into a Java Bean. Since the RSS Splunk Alert presents&#13;
meta information about saved search, the included Link in the RSS entry is then&#13;
used within the same command line application to retrieve each entry from the&#13;
saved search using the Splunk provided Java SDK.&#13;
&#13;
It is hoped that this code will be used to better serve the Splunk Java community for:&#13;
	- A method to consume RSS feeds from SPlunk with Java&#13;
	- A way to use the feed's link to gather all entries from a saved search&#13;
	- A foundation to pass search entries to higher level Java applications</summary>
  </entry>
  <entry>
    <title>Splunk Replay</title>
    <updated>2008-04-26T21:28:56+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+Replay</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+Replay" rel="alternate"/>
    <author>
      <name>Splunk</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">1361</s:key>
        <s:key name="author">Splunk</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-04-26T21:28:55+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-04-26T21:28:56+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+Replay</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Integration</s:item>
            <s:item>Custom Processing</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">1</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+Replay</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/Splunk+Replay/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">768</s:key>
        <s:key name="screenshotOriginalHeight">576</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/Splunk+Replay/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">640</s:key>
        <s:key name="screenshotHeight">480</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/Splunk+Replay/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">97</s:key>
        <s:key name="thumbnailHeight">73</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>Inspired by glTail.rb and Digg Lab’s Stack, Splunk Replay is a Flash-based, data visualization tool which “replays” your Splunk'd logfile activities in an animated layout.&#13;
&#13;
Replay generates animated barchart graphs using two extracted fields from the events it receives from Splunk. For example, if you have Splunk eat wiki data, you can plot the wiki user and wiki page they are editing, and then animate those relationships over a given time range.&#13;
&#13;
Events particles are emitted from rows on the y-axis and stack up in columns x-axis. When a new row value is created, a random color is assigned to it for the duration of the session. These colors are then used in stacked bars to illustrate the amount of activity for a given row value. Older values on both axis are cycled out if more room is needed for newer data.&#13;
&#13;
More information, and instructions for installing replay can be found on the developer's wiki: http://code.google.com/p/splunk-flash/wiki/SplunkReplay</summary>
    <category term="Splunk" label="Splunk"/>
  </entry>
  <entry>
    <title>Splunk Alert</title>
    <updated>2008-04-04T14:41:38+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+Alert</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+Alert" rel="alternate"/>
    <author>
      <name>yantisj</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">1615</s:key>
        <s:key name="author">yantisj</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2008-04-04T14:41:37+00:00</s:key>
        <s:key name="dateAddonUpdated">2008-04-04T14:41:38+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+Alert</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Event Actions</s:item>
            <s:item>Custom Processing</s:item>
            <s:item>Alerts</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">1</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+Alert</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
      </s:dict>
    </content>
    <summary>Command line utility to more easily search the splunk database, log specific errors and execute commands on a match.  Comes with several predefined searches for cisco networking, and is easily extended.&#13;
&#13;
    -s  search        Predefined search to run, use 'list' for options&#13;
    -cs string        Custom search string passed in with quotes&#13;
    -l  file          Log results to file, appends by default&#13;
    -e  email_addr    Email addresses comma separated&#13;
    -x  command       Execute a command on a match&#13;
    -t  time_restrict Suppress email alerts by time of day, use 'list' for options&#13;
    -d  days          Search over this many days in the past (default: 1)&#13;
    -m  minutes       Search over this many minutes in the past&#13;
    -c  maxnum        Max number of results (default: 100)&#13;
    -r                Reverse results, (newest to oldest)&#13;
    -w                Raw results, do not strip off timestamps&#13;
    -q                Quiet Output, suppress errors&#13;
    -v                Verbose output</summary>
    <category term="Networking" label="Networking"/>
    <category term="Network_Management" label="Network Management"/>
  </entry>
</feed>
