<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:s="http://dev.splunk.com/ns/rest">
  <title>Splunkbase Apps</title>
  <link href="http://www.splunkbase.com/api/apps/entries"/>
  <link href="http://www.splunkbase.com/api/apps/entries?splunk_version=3.4.0&amp;offset=10&amp;count=10" rel="next"/>
  <updated>2010-09-02T23:06:51+00:00</updated>
  <id>http://www.splunkbase.com/api/apps/entries?&amp;offset=0&amp;count=10</id>
  <opensearch:totalResults>122</opensearch:totalResults>
  <opensearch:itemsPerPage>10</opensearch:itemsPerPage>
  <opensearch:startIndex>1</opensearch:startIndex>
  <entry>
    <title>NetCat Shell</title>
    <updated>2010-07-30T19:33:57+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/NetCat+Shell</id>
    <link href="http://www.splunkbase.com/api/apps/entries/NetCat+Shell" rel="alternate"/>
    <author>
      <name>jklemenc</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">16</s:key>
        <s:key name="author">jklemenc</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2010-07-30T19:33:56+00:00</s:key>
        <s:key name="dateAddonUpdated">2010-07-30T19:33:57+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/NetCat+Shell</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list/>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/NetCat+Shell</s:key>
        <s:key name="iconURL"></s:key>
        <s:key name="iconWidth">0</s:key>
        <s:key name="iconHeight">0</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>Spawn a netcat listener piped to a shell. To connect, simply launch, from another machine, nc &lt;splunk server&gt; 5555 in one window and nc &lt;splunk server&gt; 6666 in another window. Type UNIX commands in the first window and view the output in the second window. WARNING!!! WARNING!!!  WARNING!!!! THIS APP IS DANGEROUS AND TO ONLY BE USED IN A CLOSED ENVIRONMENT FOR EXPERIMENTATION PURPOSES!!!! YOUR SERVER *WILL* BE COMPROMISED FROM OUTSIDERS IF YOU LEAVE NETCAT RUNNING OR OTHERWISE ACCESSIBLE BY THE INTERNET!!! YOU HAVE BEEN WARNED!!!! SIMPLY DISABLING THIS APP IN SPLUNK WILL *NOT* KILL THE LISTENERS. YOU WILL NEED TO MANUALLY KILL THE NETCAT LISTENERS FROM THE UNIX COMMAND LINE.&#13;
&#13;
This app was originally created as a proof-of-concept work.</summary>
    <category term="App" label="App"/>
  </entry>
  <entry>
    <title>TCP or UDP Sending</title>
    <updated>2010-02-25T18:04:09+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/TCP+or+UDP+Sending</id>
    <link href="http://www.splunkbase.com/api/apps/entries/TCP+or+UDP+Sending" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">436</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2010-02-03T18:01:15+00:00</s:key>
        <s:key name="dateAddonUpdated">2010-02-25T18:04:09+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/TCP+or+UDP+Sending</s:key>
        <s:key name="latestVersion">1.0.2</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Integration</s:item>
            <s:item>Inputs</s:item>
            <s:item>Clients</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/TCP+or+UDP+Sending</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/TCP+or+UDP+Sending/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/TCP+or+UDP+Sending/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">551</s:key>
        <s:key name="screenshotOriginalHeight">316</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/TCP+or+UDP+Sending/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">551</s:key>
        <s:key name="screenshotHeight">316</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/TCP+or+UDP+Sending/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">118</s:key>
        <s:key name="thumbnailHeight">68</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This distribution shows a simple approach to sending TCP or UDP data to Splunk&#13;
using included python scripts. In addition, test programs have been provided&#13;
to test TCP or UDP connections from one machine to another without using Splunk&#13;
to make sure there are no firewalls or policies that prevent connections&#13;
or receiving of data. This would be one way to debug why a forwarder cannot&#13;
send data to a port on another machine. Gunzip and Untar the distribution into SPLUNK_HOME/etc/apps and read the README.txt for instructions.</summary>
    <category term="Add-On" label="Add-On"/>
  </entry>
  <entry>
    <title>JMS Receiver for Indexing</title>
    <updated>2010-02-03T23:21:08+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/JMS+Receiver+for+Indexing</id>
    <link href="http://www.splunkbase.com/api/apps/entries/JMS+Receiver+for+Indexing" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">86</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail"></s:key>
        <s:key name="dateAddonCreated">2010-02-03T23:21:07+00:00</s:key>
        <s:key name="dateAddonUpdated">2010-02-03T23:21:08+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/JMS+Receiver+for+Indexing</s:key>
        <s:key name="latestVersion">1.0</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Scripted Inputs</s:item>
            <s:item>Inputs</s:item>
            <s:item>Custom Processing</s:item>
            <s:item>Clients</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/JMS+Receiver+for+Indexing</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/JMS+Receiver+for+Indexing/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/JMS+Receiver+for+Indexing/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">170</s:key>
        <s:key name="screenshotOriginalHeight">113</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/JMS+Receiver+for+Indexing/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">170</s:key>
        <s:key name="screenshotHeight">113</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/JMS+Receiver+for+Indexing/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">110</s:key>
        <s:key name="thumbnailHeight">73</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This distribution is a working example for indexing messages that are sent to JMS Queues.&#13;
Although the example heavily relies on WebLogic Server 10.3, it could be modified to work with&#13;
any JMS provider. Messages are delivered to a JMS Queue and Splunk is configured to run&#13;
a scripted input once to call a JMS Queue consumer. Every message the consumer receives&#13;
will be sent to standard output to be indexed. Although the distribution has been built&#13;
on Windows, it should be able to run on any platform supported by Splunk and the JMS&#13;
provider. To begin with, gunzip and untar the distribution into&#13;
SPLUNK_HOME\etc\apps and follow the instructions in the README.txt</summary>
    <category term="Add-On" label="Add-On"/>
  </entry>
  <entry>
    <title>Splunk for IMAP</title>
    <updated>2009-11-17T01:32:28+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Splunk+for+IMAP</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Splunk+for+IMAP" rel="alternate"/>
    <author>
      <name>erik</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">4067</s:key>
        <s:key name="author">erik</s:key>
        <s:key name="contactEmail">erik@splunk.com</s:key>
        <s:key name="dateAddonCreated">2007-08-19T04:54:12+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-11-17T01:32:28+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Splunk+for+IMAP</s:key>
        <s:key name="latestVersion">1.20</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Searches</s:item>
            <s:item>Scripted Inputs</s:item>
            <s:item>Inputs</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">4.0</s:key>
        <s:key name="ratingCount">4</s:key>
        <s:key name="bundle_count">0</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Splunk+for+IMAP</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/Splunk+for+IMAP/icon.jpg</s:key>
        <s:key name="iconWidth">41</s:key>
        <s:key name="iconHeight">33</s:key>
        <s:key name="screenshotOriginalURL">http://www.splunkbase.com/apps:screenshot/original/Splunk+for+IMAP/screenshot.jpg</s:key>
        <s:key name="screenshotOriginalWidth">129</s:key>
        <s:key name="screenshotOriginalHeight">88</s:key>
        <s:key name="screenshotURL">http://www.splunkbase.com/apps:screenshot/scaled/Splunk+for+IMAP/screenshot.jpg</s:key>
        <s:key name="screenshotWidth">129</s:key>
        <s:key name="screenshotHeight">88</s:key>
        <s:key name="thumbnailURL">http://www.splunkbase.com/apps:screenshot/thumb/Splunk+for+IMAP/screenshot.jpg</s:key>
        <s:key name="thumbnailWidth">107</s:key>
        <s:key name="thumbnailHeight">73</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This application will continually download mail from an imap account where it is indexed by a Splunk server. You can do cool things like see how often you get mail from someone, graph by size, time, etc.</summary>
    <category term="App" label="App"/>
  </entry>
  <entry>
    <title>Indexing events from Multicast address</title>
    <updated>2009-10-15T21:45:21+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Indexing+events+from+Multicast+address</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Indexing+events+from+Multicast+address" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">238</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail">nimish@splunk.com</s:key>
        <s:key name="dateAddonCreated">2009-09-30T18:58:11+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-10-15T21:45:21+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Indexing+events+from+Multicast+address</s:key>
        <s:key name="latestVersion">1.0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Scripted Inputs</s:item>
            <s:item>Integration</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Indexing+events+from+Multicast+address</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/Indexing+events+from+Multicast+address/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This app contains an example scripted input to test receiving and indexing&#13;
data that is sent to a multicast address and port. &#13;
&#13;
&#13;
I have simply used publicly available code to show one way to get scripted input&#13;
to listen on a multicast address and port to index mutlticast data. Generally,&#13;
it is not recommended to broadcast log files to all machines as UDP receiving&#13;
may be unreliable and flooding the network with packets that are only going to&#13;
be received by a few machines is inefficient. However, if there are&#13;
applications that need to multicast signal data and you are interested in&#13;
indexing and searching this data, the provided distribution may be useful.&#13;
&#13;
Read the README.txt for configuration</summary>
    <category term="Add-On" label="Add-On"/>
  </entry>
  <entry>
    <title>Audible Alerts using Nabaztag:Tag (Wifi Rabbit)</title>
    <updated>2009-10-15T21:39:58+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Audible+Alerts+using+Nabaztag%3ATag+%28Wifi+Rabbit%29</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Audible+Alerts+using+Nabaztag%3ATag+%28Wifi+Rabbit%29" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">188</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail">nimish@splunk.com</s:key>
        <s:key name="dateAddonCreated">2009-04-10T19:18:03+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-10-15T21:39:58+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Audible+Alerts+using+Nabaztag%3ATag+%28Wifi+Rabbit%29</s:key>
        <s:key name="latestVersion">1.0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Integration</s:item>
            <s:item>Alerts</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Audible+Alerts+using+Nabaztag%3ATag+%28Wifi+Rabbit%29</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/Audible+Alerts+using+Nabaztag%3ATag+%28Wifi+Rabbit%29/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This application is an example of sending audible alerts to a device using the REST API of the device. The idea is that there are times when you would want to receive alerts beyond the usual text based alerts, especially when you may be in a remote location.&#13;
&#13;
This script runs as a scripted alert in Splunk to send an audible alert to&#13;
a Nabaztag:Tag (robot rabbit from http://www.violet.net/)&#13;
whenever the alert conditions are met. It uses Violet's REST API to send&#13;
the message. Currently, the script uses daily, weekday and weekend to control what days&#13;
the email alert should be sent. It also provides start and end hours when&#13;
the alert should be active.&#13;
&#13;
Installation:&#13;
&#13;
Use tar zxvf to uncompress and untar the distribution. Then, read the README for further instructions.&#13;
&#13;
Requirements: Wireless Router and Nabaztag:Tag</summary>
    <category term="Add-On" label="Add-On"/>
  </entry>
  <entry>
    <title>Encrypt and Decrypt data within Events</title>
    <updated>2009-10-15T21:35:43+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Encrypt+and+Decrypt+data+within+Events</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Encrypt+and+Decrypt+data+within+Events" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">202</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail">nimish@splunk.com</s:key>
        <s:key name="dateAddonCreated">2009-10-07T17:23:55+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-10-15T21:35:43+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Encrypt+and+Decrypt+data+within+Events</s:key>
        <s:key name="latestVersion">1.0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Search Commands</s:item>
            <s:item>Inputs</s:item>
            <s:item>Custom Processing</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">1</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Encrypt+and+Decrypt+data+within+Events</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/Encrypt+and+Decrypt+data+within+Events/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>The purpose of this distribution is to create an easy way to encrypt data&#13;
within events and decrypt data at search time depending on the role. The&#13;
distribution uses pyDes available at http://twhiteman.netfirms.com/des.html&#13;
&#13;
The basic idea is to first encrypt data within an event and produce a new file&#13;
with the same content as before, but with the data matching group(1) in a&#13;
regular expression encrypted and saved on disk using base64. The next thing&#13;
to do is index the newly required file into Splunk with a sourcetype.&#13;
&#13;
At search time, you will then be able to decrypt the data within the event&#13;
based on your role's ability to run the supplied decrypt command. Read the README.txt for installation and usage.</summary>
    <category term="Add-On" label="Add-On"/>
  </entry>
  <entry>
    <title>RSS Scripted Input</title>
    <updated>2009-10-15T21:15:05+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/RSS+Scripted+Input</id>
    <link href="http://www.splunkbase.com/api/apps/entries/RSS+Scripted+Input" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">363</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail">nimish@splunk.com</s:key>
        <s:key name="dateAddonCreated">2009-08-13T23:40:34+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-10-15T21:15:05+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/RSS+Scripted+Input</s:key>
        <s:key name="latestVersion">1.0.2</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Scripted Inputs</s:item>
            <s:item>Inputs</s:item>
            <s:item>Fields</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/RSS+Scripted+Input</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/RSS+Scripted+Input/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This is a simple application to take the content of any RSS feed and index&#13;
its metadata (date, title, link, and description) into Splunk. A scripted input calls rss.sh every 600&#13;
seconds, which in turn, calls the supplied Python program, rssfeed.py to&#13;
gather the rss feeds. RSS feeds are supplied via a file passed on the command&#13;
line. A sample file, feeds.txt, is provided for testing. This program uses the&#13;
open source feedparser from www.feedparser.org for its RSS parser.&#13;
&#13;
Installation:&#13;
&#13;
Gunzip and un tar the distirbution into $SPLUNK_HOME/etc/apps and read the README.txt</summary>
    <category term="Add-On" label="Add-On"/>
  </entry>
  <entry>
    <title>Log POST or GET Request Parameters</title>
    <updated>2009-10-15T21:10:36+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Log+POST+or+GET+Request+Parameters</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Log+POST+or+GET+Request+Parameters" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">1786</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail">nimish@splunk.com</s:key>
        <s:key name="dateAddonCreated">2009-02-18T23:39:11+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-10-15T21:10:36+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Log+POST+or+GET+Request+Parameters</s:key>
        <s:key name="latestVersion">1.1.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Integration</s:item>
            <s:item>Inputs</s:item>
            <s:item>Custom Processing</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Log+POST+or+GET+Request+Parameters</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/Log+POST+or+GET+Request+Parameters/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This application consists of a servlet that captures the POST and/or GET&#13;
parameters for any HTTP request and sends to standard output a set of&#13;
&lt;tag&gt;=&lt;value&gt; terms seen as an event in Splunk. Because tag=value are the&#13;
terms in the events, automatic field extraction for search and reports will&#13;
occur for these terms. The purpose of this boiler plate Java Servlet is to&#13;
serve as a parameter collector for HTTP POST and GET requests that can be&#13;
customized for deployment.&#13;
&#13;
The servlet developed here was tested on Apache Tomcat 6.x, although it should&#13;
work in any servlet container. To further solidify it's usage, the user&#13;
may want to investigate using log4j as the framework for log collection. In&#13;
the Tomcat implementation, the output is captured in a configurable log rotated&#13;
file to be monitored by Splunk.&#13;
&#13;
*** OPTIONAL ***&#13;
This version also includes a servlet that uses the log4j framework.&#13;
&#13;
tar -zxvf the distribution and read the README for installation notes.</summary>
    <category term="Add-On" label="Add-On"/>
  </entry>
  <entry>
    <title>Use Python Mail for Scripted Alerts</title>
    <updated>2009-10-15T21:03:42+00:00</updated>
    <id>http://www.splunkbase.com/api/apps/entries/Use+Python+Mail+for+Scripted+Alerts</id>
    <link href="http://www.splunkbase.com/api/apps/entries/Use+Python+Mail+for+Scripted+Alerts" rel="alternate"/>
    <author>
      <name>ndoshi</name>
    </author>
    <content type="text/xml">
      <s:dict>
        <s:key name="downloads">574</s:key>
        <s:key name="author">ndoshi</s:key>
        <s:key name="contactEmail">nimish@splunk.com</s:key>
        <s:key name="dateAddonCreated">2009-03-03T20:10:07+00:00</s:key>
        <s:key name="dateAddonUpdated">2009-10-15T21:03:42+00:00</s:key>
        <s:key name="price">Free</s:key>
        <s:key name="license">Creative Commons</s:key>
        <s:key name="licenseURL">http://www.splunkbase.com/apps:license/Use+Python+Mail+for+Scripted+Alerts</s:key>
        <s:key name="latestVersion">1.0.1</s:key>
        <s:key name="types">
          <s:list>
            <s:item>Custom Processing</s:item>
            <s:item>Alerts</s:item>
          </s:list>
        </s:key>
        <s:key name="rating">No Data</s:key>
        <s:key name="ratingCount">0</s:key>
        <s:key name="bundle_count">1</s:key>
        <s:key name="appURL">http://www.splunkbase.com/apps/Use+Python+Mail+for+Scripted+Alerts</s:key>
        <s:key name="iconURL">http://www.splunkbase.com/apps:screenshot/original/Use+Python+Mail+for+Scripted+Alerts/icon.jpg</s:key>
        <s:key name="iconWidth">36</s:key>
        <s:key name="iconHeight">36</s:key>
        <s:key name="screenshotOriginalURL"></s:key>
        <s:key name="screenshotOriginalWidth">0</s:key>
        <s:key name="screenshotOriginalHeight">0</s:key>
        <s:key name="screenshotURL"></s:key>
        <s:key name="screenshotWidth">0</s:key>
        <s:key name="screenshotHeight">0</s:key>
        <s:key name="thumbnailURL"></s:key>
        <s:key name="thumbnailWidth">0</s:key>
        <s:key name="thumbnailHeight">0</s:key>
        <s:key name="splunkMinVersion">3.0.0</s:key>
        <s:key name="splunkMaxVersion">4.999.999</s:key>
      </s:dict>
    </content>
    <summary>This script runs as a scripted alert in Splunk to send mail to recipients&#13;
whenever the alert conditions are met. It is similar in concept to the Javamail application available on Splunkbase. It uses Python to send the message.&#13;
The intent is to provide a framework to control when email should be sent.&#13;
Currently, the script uses Daily, Weekday, and Weekend to control what days&#13;
the email alert should be sent. With this in mind the included Python program&#13;
can be modified to also include what hours of the day email should be sent.&#13;
&#13;
Installation:&#13;
&#13;
Use tar zxvf to uncompress and untar the distribution and read the README.txt.</summary>
    <category term="Add-On" label="Add-On"/>
  </entry>
</feed>
