<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:s="http://dev.splunk.com/ns/rest">
  <title>Negative Searching Demo Bundle</title>
  <updated>2007-09-07T04:18:53+00:00</updated>
  <id>http://www.splunkbase.com/api/apps/entries/Negative+Searching+Demo+Bundle</id>
  <author>
    <name>maverick</name>
  </author>
  <category term="Compliance" label="Compliance"/>
  <subtitle>This bundle, created jointly by Maverick and Stephen Sorkin, demonstrates a way to perform negative searches by indexing known patterns and catching anomalous patterns into a separate index.</subtitle>
  <entry>
    <title>1.0</title>
    <updated>2007-08-13T04:17:04+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/Negative+Searching+Demo+Bundle/1.0</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Negative+Searching+Demo+Bundle/1.0" rel="alternate"/>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">753</s:key>
        <s:key name="author">maverick</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2007-08-13T04:17:04+00:00</s:key>
        <s:key name="dateAddonUpdated">2007-09-07T04:18:53+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Negative+Searching+Demo+Bundle</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Reports</s:item>
            <s:item>Inputs</s:item>
            <s:item>Fields</s:item>
            <s:item>Alerts</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">1</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Negative+Searching+Demo+Bundle</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0.0</s:key>
        <s:key name="splunkMaxVersion">3.999.999</s:key>
        <s:key name="islatest">True</s:key>
      </s:dict>
    </content>
  </entry>
</feed>
