<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>Latest SplunkBase Applications (Network IDS / IPS)</title>
    <link>http://www.splunkbase.com/feed/apps.rss/All/Technologies/Security_Applications/Network_IDS_-_IPS</link>
    <description>Latest SplunkBase Applications in category Network IDS / IPS</description>

    <item>
      <title>Splunk for Snort</title>
      <author>Splunk</author>
      <pubDate>Wed, 20 Aug 2008 18:31:47 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/Network_IDS_-_IPS/app:Splunk+for+Snort</link>
      <guid isPermaLink="false">c4de85d8c07f02e7aae87c5d2cf2f925</guid>
      <description>This application applies to Snort alert logs, bringing their field names into compliance with the Splunk interface standard (see http://www.splunkbase.com/howtos/Splunk/howto:Understanding_Splunk&#039;s_interface_standards).</description>
    </item>
    <item>
      <title>Sancp/Sguil Add-on</title>
      <author>araitz</author>
      <pubDate>Tue, 18 Dec 2007 19:25:57 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/Network_IDS_-_IPS/app:Sancp%7FSguil+Add-on</link>
      <guid isPermaLink="false">86554233c6f753ca862119b8d13bdb0e</guid>
      <description>This bundle indexes sancp logs when sancp is patched with the sguil output patch, extracts the fields, then sends to a processor which converts the decimal IP addresses to dotted format.</description>
    </item>
    <item>
      <title>Snort fields</title>
      <author>mfratto</author>
      <pubDate>Mon, 01 Oct 2007 14:36:44 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/All/Technologies/Security_Applications/Network_IDS_-_IPS/app:Snort+fields</link>
      <guid isPermaLink="false">786e4729ca04060a32e4dee2ba912b4d</guid>
      <description>Extracts snort 2.6 fields which can be used in reporting.</description>
    </item>

  </channel>
</rss>