<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>Latest SplunkBase Applications (Security Applications)</title>
    <link>http://www.splunkbase.com/feed/apps.rss/All/Technologies/Security_Applications</link>
    <description>Latest SplunkBase Applications in category Security Applications</description>

    <item>
      <title>BSM Audit log loader</title>
      <author>erik</author>
      <pubDate>Wed, 17 Dec 2008 02:26:36 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/app:BSM+Audit+log+loader</link>
      <guid isPermaLink="false">9ddf0536d7b1a8d6cb7c41549017c269</guid>
      <description>This app will on an interval convert local audit logs to text while keeping track of the last time it ran as to not get duplicates. Run this app on a server that is running bsm to capture audit logs before they roll.</description>
    </item>
    <item>
      <title>Splunk for Snare</title>
      <author>Splunk</author>
      <pubDate>Wed, 01 Oct 2008 22:28:16 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/app:Splunk+for+Snare</link>
      <guid isPermaLink="false">d1622685eb55d92d97a3d0883d347583</guid>
      <description>The Splunk for Snare application offers eventtypes and field extractions for Snare collecting Windows events.</description>
    </item>
    <item>
      <title>Splunk for Snort</title>
      <author>Splunk</author>
      <pubDate>Wed, 20 Aug 2008 18:31:47 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/app:Splunk+for+Snort</link>
      <guid isPermaLink="false">c4de85d8c07f02e7aae87c5d2cf2f925</guid>
      <description>This application applies to Snort alert logs, bringing their field names into compliance with the Splunk interface standard (see http://www.splunkbase.com/howtos/Splunk/howto:Understanding_Splunk&#039;s_interface_standards).</description>
    </item>
    <item>
      <title>AfterGlow Graphing</title>
      <author>raffy</author>
      <pubDate>Wed, 13 Aug 2008 21:53:02 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/app:AfterGlow+Graphing</link>
      <guid isPermaLink="false">4f2e1c0df533194486f4ec74e385ed66</guid>
      <description>This new search processor enables the generation of link graphs through Splunk. Make sure you follow the instructions in the README (once installed, located in etc/apps/afterglow) to configure the application!</description>
    </item>
    <item>
      <title>Squid Web Proxy</title>
      <author>rataide</author>
      <pubDate>Thu, 10 Jul 2008 18:58:23 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/app:Squid+Web+Proxy</link>
      <guid isPermaLink="false">28b667bd334e8ba8a3d4e9759d5b1d12</guid>
      <description>== Squid Application ==

This application will provide additional field extractions for Squid Proxy Server access_log files

== Using Squid Application ==

At search time the following additional fields will be available:

- duration
- clientip
- action
- http_status
- bytes
- method
- uri
- proto
- uri_host
- uri_port
- uri_path
- username
- hierarchy
- server_ip
- content_type</description>
    </item>
    <item>
      <title>Netcache fields, inputs, and event types</title>
      <author>Splunk</author>
      <pubDate>Mon, 14 Jan 2008 18:30:11 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/app:Netcache+fields%2C+inputs%2C+and+event+types</link>
      <guid isPermaLink="false">3dda8837097357ffcdb02b8489237812</guid>
      <description>This add-on normalizes Netcache fields so that other Splunk applications understand them.</description>
    </item>
    <item>
      <title>Sancp/Sguil Add-on</title>
      <author>araitz</author>
      <pubDate>Tue, 18 Dec 2007 19:25:57 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/app:Sancp%7FSguil+Add-on</link>
      <guid isPermaLink="false">86554233c6f753ca862119b8d13bdb0e</guid>
      <description>This bundle indexes sancp logs when sancp is patched with the sguil output patch, extracts the fields, then sends to a processor which converts the decimal IP addresses to dotted format.</description>
    </item>
    <item>
      <title>Snort fields</title>
      <author>mfratto</author>
      <pubDate>Mon, 01 Oct 2007 14:36:44 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/app:Snort+fields</link>
      <guid isPermaLink="false">786e4729ca04060a32e4dee2ba912b4d</guid>
      <description>Extracts snort 2.6 fields which can be used in reporting.</description>
    </item>
    <item>
      <title>Nmap Scripted Input &amp; Field Extraction</title>
      <author>araitz</author>
      <pubDate>Fri, 28 Sep 2007 01:13:34 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/app:Nmap+Scripted+Input+%26+Field+Extraction</link>
      <guid isPermaLink="false">94b5178420bfbcd37d4201914be5ac85</guid>
      <description>Want to put your Nmap output into Splunk?  

Check out this add-on, which will parse your grepable Nmap output into a scripted input and then perform some field extraction on the data.</description>
    </item>
    <item>
      <title>Nessus Bundle</title>
      <author>maverick</author>
      <pubDate>Fri, 07 Sep 2007 04:20:12 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/app:Nessus+Bundle</link>
      <guid isPermaLink="false">761b6685ad2bb1f397ab50934bd0affe</guid>
      <description>This bundle extracts the common fields from a Nessus Vulnerability Scanner log file, such as the hostname, port, script id, and type.</description>
    </item>
    <item>
      <title>adds support for anonymizing log files at index time</title>
      <author>carasso</author>
      <pubDate>Mon, 20 Aug 2007 01:23:57 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/app:adds+support+for+anonymizing+log+files+at+index+time</link>
      <guid isPermaLink="false">68d72996a68ce809bc4d3c7b54916d9e</guid>
      <description>anonymizes ip address as 127.0.0.1 (localhost); 
email addresses as user@domain.com  ;                                                                                                                                                                        
social-security-numbers as 555-00-0000;
password/passwd looking values as &#039;password&#039;                                                                                                           ;
username/userid/login/user looking values as &#039;bob&#039;.</description>
    </item>

  </channel>
</rss>