<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>Latest SplunkBase Applications (Custom Processing)</title>
    <link>http://www.splunkbase.com/feed/apps.rss/Custom%20Processing</link>
    <description>Latest SplunkBase Applications filtered by Custom Processing</description>

    <item>
      <title>Splunk for VMware ESX Management</title>
      <author>erik</author>
      <pubDate>Wed, 03 Sep 2008 00:35:48 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Custom%20Processing/app:Splunk+for+VMware+ESX+Management</link>
      <guid isPermaLink="false">eaba98b4f8386d4ed8552c81028cf465</guid>
      <description>This Splunk application manages VMware ESX and VMware VirtualCenter systems.  It includes inputs, indexing, searches, reports and dashboards.</description>
    </item>
    <item>
      <title>Consuming Splunk RSS Feeds in Java</title>
      <author>nimishd</author>
      <pubDate>Wed, 13 Aug 2008 17:07:55 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Custom%20Processing/app:Consuming+Splunk+RSS+Feeds+in+Java</link>
      <guid isPermaLink="false">7a4842c44867d34be1ca7146c4cc6594</guid>
      <description>This application demonstrates how to consume an RSS alert feed in Java from any
saved search from Splunk. It uses Sun&#039;s RSS parser (included) to gather the feed
and breaks up the fields into a Java Bean. Since the RSS Splunk Alert presents
meta information about saved search, the included Link in the RSS entry is then
used within the same command line application to retrieve each entry from the
saved search using the Splunk provided Java SDK.

It is hoped that this code will be used to better serve the Splunk Java community for:
	- A method to consume RSS feeds from SPlunk with Java
	- A way to use the feed&#039;s link to gather all entries from a saved search
	- A foundation to pass search entries to higher level Java applications</description>
    </item>
    <item>
      <title>Splunk Replay</title>
      <author>Splunk</author>
      <pubDate>Sat, 26 Apr 2008 21:28:56 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Custom%20Processing/app:Splunk+Replay</link>
      <guid isPermaLink="false">d63730ba49f07050b89da3eb523ec6a8</guid>
      <description>Inspired by glTail.rb and Digg Lab’s Stack, Splunk Replay is a Flash-based, data visualization tool which “replays” your Splunk&#039;d logfile activities in an animated layout.

Replay generates animated barchart graphs using two extracted fields from the events it receives from Splunk. For example, if you have Splunk eat wiki data, you can plot the wiki user and wiki page they are editing, and then animate those relationships over a given time range.

Events particles are emitted from rows on the y-axis and stack up in columns x-axis. When a new row value is created, a random color is assigned to it for the duration of the session. These colors are then used in stacked bars to illustrate the amount of activity for a given row value. Older values on both axis are cycled out if more room is needed for newer data.

More information, and instructions for installing replay can be found on the developer&#039;s wiki: http://code.google.com/p/splunk-flash/wiki/SplunkReplay</description>
    </item>
    <item>
      <title>Splunk Alert</title>
      <author>yantisj</author>
      <pubDate>Fri, 04 Apr 2008 14:41:38 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Custom%20Processing/app:Splunk+Alert</link>
      <guid isPermaLink="false">8e2c2a15568cedc48cb46355dbdd805b</guid>
      <description>Command line utility to more easily search the splunk database, log specific errors and execute commands on a match.  Comes with several predefined searches for cisco networking, and is easily extended.

    -s  search        Predefined search to run, use &#039;list&#039; for options
    -cs string        Custom search string passed in with quotes
    -l  file          Log results to file, appends by default
    -e  email_addr    Email addresses comma separated
    -x  command       Execute a command on a match
    -t  time_restrict Suppress email alerts by time of day, use &#039;list&#039; for options
    -d  days          Search over this many days in the past (default: 1)
    -m  minutes       Search over this many minutes in the past
    -c  maxnum        Max number of results (default: 100)
    -r                Reverse results, (newest to oldest)
    -w                Raw results, do not strip off timestamps
    -q                Quiet Output, suppress errors
    -v                Verbose output</description>
    </item>
    <item>
      <title>Splunk Parse</title>
      <author>shaggy</author>
      <pubDate>Tue, 18 Mar 2008 22:06:36 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Custom%20Processing/app:Splunk+Parse</link>
      <guid isPermaLink="false">6d1bf077e7913237de81dfbcae840b6c</guid>
      <description>Splunk Parse (splunk_parse.py) is a python script you can set as your alert action on a saved search. It reads in the fields a saved search passing along and parses the corresponding saved search log file which is in CSV format. The parsing spits out the originating host and the full original problem. In this version it&#039;s feed to my ticketing system, but the output action can be easily changed.</description>
    </item>
    <item>
      <title>Sancp/Sguil Add-on</title>
      <author>araitz</author>
      <pubDate>Tue, 18 Dec 2007 19:25:57 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Custom%20Processing/app:Sancp%7FSguil+Add-on</link>
      <guid isPermaLink="false">86554233c6f753ca862119b8d13bdb0e</guid>
      <description>This bundle indexes sancp logs when sancp is patched with the sguil output patch, extracts the fields, then sends to a processor which converts the decimal IP addresses to dotted format.</description>
    </item>
    <item>
      <title>EMC Smarts archive log</title>
      <author>will</author>
      <pubDate>Tue, 11 Dec 2007 00:46:47 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Custom%20Processing/app:EMC+Smarts+archive+log</link>
      <guid isPermaLink="false">74477be0eea74f4af9e511e74a5918a2</guid>
      <description>Line merging rule for EMC Smarts archive log</description>
    </item>
    <item>
      <title>Enable SSL in Splunk</title>
      <author>deeann</author>
      <pubDate>Tue, 02 Oct 2007 20:22:09 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Custom%20Processing/app:Enable+SSL+in+Splunk</link>
      <guid isPermaLink="false">773eae93545d03bcc0c19629fe23724d</guid>
      <description>A quick and simple add-on that enables SSL for your pre-3.2 Splunk server and Web interface.</description>
    </item>
    <item>
      <title>adds support for anonymizing log files at index time</title>
      <author>carasso</author>
      <pubDate>Mon, 20 Aug 2007 01:23:57 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Custom%20Processing/app:adds+support+for+anonymizing+log+files+at+index+time</link>
      <guid isPermaLink="false">68d72996a68ce809bc4d3c7b54916d9e</guid>
      <description>anonymizes ip address as 127.0.0.1 (localhost); 
email addresses as user@domain.com  ;                                                                                                                                                                        
social-security-numbers as 555-00-0000;
password/passwd looking values as &#039;password&#039;                                                                                                           ;
username/userid/login/user looking values as &#039;bob&#039;.</description>
    </item>
    <item>
      <title>Ironport field extractions</title>
      <author>ssorkin</author>
      <pubDate>Fri, 17 Aug 2007 20:07:35 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Custom%20Processing/app:Ironport+field+extractions</link>
      <guid isPermaLink="false">54b9c491e0030048e9dc8718f26927d9</guid>
      <description>Provides file classification, date extraction, and extractions for ironport data.</description>
    </item>
    <item>
      <title>feorlen_twitter_alert</title>
      <author>andrea</author>
      <pubDate>Mon, 13 Aug 2007 03:26:17 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Custom%20Processing/app:feorlen_twitter_alert</link>
      <guid isPermaLink="false">9fcc3a25cf99144267c02b2d69c03227</guid>
      <description>Example of using a 3rd party REST endpoint with a Splunk custom processor. Post a message to Twitter for sourcetype::access_common events containing the string &quot;wikipedia&quot; and add status info to the event so it gets indexed. Includes C++ source and osx-i386 binary.</description>
    </item>

  </channel>
</rss>