<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>Latest SplunkBase Applications (Fields)</title>
    <link>http://www.splunkbase.com/feed/apps.rss/Fields</link>
    <description>Latest SplunkBase Applications filtered by Fields</description>

    <item>
      <title>Splunk for Change Management</title>
      <author>Splunk</author>
      <pubDate>Fri, 05 Sep 2008 23:26:14 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Splunk+for+Change+Management</link>
      <guid isPermaLink="false">95d9940cef25692b9483d352c8ed494c</guid>
      <description>Splunk for Change Management provides predefined reports and dashboards to facilitate change auditing, change detection, change reporting, change validation and incident response based on change events, change tickets and configuration files.</description>
    </item>
    <item>
      <title>Splunk for Network Security</title>
      <author>Splunk</author>
      <pubDate>Thu, 04 Sep 2008 23:47:13 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Splunk+for+Network+Security</link>
      <guid isPermaLink="false">8a48676a95f0f7c3a5c567aa9f159b0e</guid>
      <description>The Splunk Network Security application offers a set of reports, saved searches, and dashboards, as well as corresponding alerts that you can use to monitor your firewalls, intrusion detection and prevention systems, as well as operating systems.</description>
    </item>
    <item>
      <title>Splunk for CISCO PIX</title>
      <author>Splunk</author>
      <pubDate>Thu, 04 Sep 2008 16:51:01 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Splunk+for+CISCO+PIX</link>
      <guid isPermaLink="false">740e6413701ddc9ceccf7ac81e2f90c6</guid>
      <description>Cisco PIX firewall log bundle that indexes and extracts common fields, normalizing PIX firewall logs so they are Splunk-compliant and will work with other Splunk applications.</description>
    </item>
    <item>
      <title>Splunk for UNIX</title>
      <author>Splunk</author>
      <pubDate>Thu, 21 Aug 2008 18:30:59 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Splunk+for+UNIX</link>
      <guid isPermaLink="false">94bc942e8cd8c90bf64d566700735e5d</guid>
      <description>The Splunk for UNIX application is a compilation of a dashboard, saved searches, eventtypes, and field extractions that work for various flavors of UNIX. In addition, the application also ships with a set of scripted inputs that can be used to monitor UNIX machines. Inputs like top, ps, vmstat, and netstat are supported.</description>
    </item>
    <item>
      <title>Splunk for Snort</title>
      <author>Splunk</author>
      <pubDate>Wed, 20 Aug 2008 18:31:47 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Splunk+for+Snort</link>
      <guid isPermaLink="false">c4de85d8c07f02e7aae87c5d2cf2f925</guid>
      <description>This application applies to Snort alert logs, bringing their field names into compliance with the Splunk interface standard (see http://www.splunkbase.com/howtos/Splunk/howto:Understanding_Splunk&#039;s_interface_standards).</description>
    </item>
    <item>
      <title>OpenBSD Packet Filter</title>
      <author>raffy</author>
      <pubDate>Mon, 18 Aug 2008 23:24:52 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:OpenBSD+Packet+Filter</link>
      <guid isPermaLink="false">2f14c07247b6405bdfd89eccd3029a13</guid>
      <description>This bundle contains field extractions and eventtypes for OpenBSD firewall events.</description>
    </item>
    <item>
      <title>IPFW Firewall</title>
      <author>raffy</author>
      <pubDate>Mon, 18 Aug 2008 23:21:49 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:IPFW+Firewall</link>
      <guid isPermaLink="false">916954b39e6fa95fba91c6ba82c82f95</guid>
      <description>This application contains field extractions and eventtypes for IPFW firewall log files.</description>
    </item>
    <item>
      <title>Web Page Monitor</title>
      <author>erik</author>
      <pubDate>Fri, 15 Aug 2008 03:17:24 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Web+Page+Monitor</link>
      <guid isPermaLink="false">9f5cf71efea79575dcb8050cb6518d02</guid>
      <description>This bundle will check a set of webpages every interval and index the result, time, size and optionally content and or crc of page(s). Its cool to do searches to see when your pages change, take long to load, or many other cool things.</description>
    </item>
    <item>
      <title>Squid Web Proxy</title>
      <author>rataide</author>
      <pubDate>Thu, 10 Jul 2008 18:58:23 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Squid+Web+Proxy</link>
      <guid isPermaLink="false">28b667bd334e8ba8a3d4e9759d5b1d12</guid>
      <description>== Squid Application ==

This application will provide additional field extractions for Squid Proxy Server access_log files

== Using Squid Application ==

At search time the following additional fields will be available:

- duration
- clientip
- action
- http_status
- bytes
- method
- uri
- proto
- uri_host
- uri_port
- uri_path
- username
- hierarchy
- server_ip
- content_type</description>
    </item>
    <item>
      <title>Splunk for Citrix XenServer Management</title>
      <author>Splunk</author>
      <pubDate>Wed, 28 May 2008 22:12:24 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Splunk+for+Citrix+XenServer+Management</link>
      <guid isPermaLink="false">931cc18d8db03fec361e7e2dfd2c99bd</guid>
      <description>This Splunk application manages Citrix XenServers.  It includes inputs, indexing, searches, reports, dashboards and field actions.</description>
    </item>
    <item>
      <title>CheckPoint OPSEC LEA Application</title>
      <author>Splunk</author>
      <pubDate>Fri, 16 May 2008 23:30:02 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:CheckPoint+OPSEC+LEA+Application</link>
      <guid isPermaLink="false">3d146d4b3b3e0cb8086f5f952a40e868</guid>
      <description>This application contains an OPSEC LEA application to drop into Splunk 3.0 or later, offering a client, event types, and field extractions. It functions on Linux and on Solaris with gmake and gcc installed.
The application conforms with the Splunk application standard, meaning that it uses common field names for its data.</description>
    </item>
    <item>
      <title>twiki logs</title>
      <author>nick</author>
      <pubDate>Wed, 05 Mar 2008 21:37:27 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:twiki+logs</link>
      <guid isPermaLink="false">5a4fe80afcf0571e3f24ed6bf20bf0ae</guid>
      <description>Contains the basic extractions as well as some saved searches, reports, event types, and custom dashboard modules.</description>
    </item>
    <item>
      <title>nscreen</title>
      <author>jon</author>
      <pubDate>Tue, 04 Mar 2008 00:49:02 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:nscreen</link>
      <guid isPermaLink="false">ed90be4ca3bd609a480731d22e9e2bcf</guid>
      <description>This bundle is for field extraction and reporting on netscreen firewalls</description>
    </item>
    <item>
      <title>Bladelogic NSH and Agent Logs</title>
      <author>will</author>
      <pubDate>Mon, 03 Mar 2008 21:42:42 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Bladelogic+NSH+and+Agent+Logs</link>
      <guid isPermaLink="false">29db097c416a52e8bcb94a860b4ea713</guid>
      <description>This bundle contains field extractions for the Bladelogic agent and nsh log files. Some sample reports are also included.</description>
    </item>
    <item>
      <title>Juniper SSG (aka Netscreen) blocked URL search fields</title>
      <author>btrnoc</author>
      <pubDate>Fri, 15 Feb 2008 09:08:41 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Juniper+SSG+%28aka+Netscreen%29+blocked+URL+search+fields</link>
      <guid isPermaLink="false">fb19f86c89e0238a5ab536c7fa6fad3f</guid>
      <description>Juniper SSG (aka Netscreen) log that indexes and extracts URL blocked entries, such as source and destination addresses, URL and category</description>
    </item>
    <item>
      <title>Windows logs through Snare fields, inputs, and event types</title>
      <author>Splunk</author>
      <pubDate>Mon, 14 Jan 2008 18:36:24 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Windows+logs+through+Snare+fields%2C+inputs%2C+and+event+types</link>
      <guid isPermaLink="false">d1622685eb55d92d97a3d0883d347583</guid>
      <description>This add-on applies to Windows logs captured through Snare, bringing their field names into compliance with the Splunk interface standard (see http://www.splunkbase.com/howtos/Splunk/howto:Understanding_Splunk&#039;s_interface_standards).</description>
    </item>
    <item>
      <title>Sendmail fields, inputs, and event types</title>
      <author>Splunk</author>
      <pubDate>Mon, 14 Jan 2008 18:33:07 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Sendmail+fields%2C+inputs%2C+and+event+types</link>
      <guid isPermaLink="false">e6e1c2112286c360aa09c203dcdad2ab</guid>
      <description>This add-on applies to Sendmail logs, bringing their field names into compliance with the Splunk interface standard (see http://www.splunkbase.com/howtos/Splunk/howto:Understanding_Splunk&#039;s_interface_standards).</description>
    </item>
    <item>
      <title>Netcache fields, inputs, and event types</title>
      <author>Splunk</author>
      <pubDate>Mon, 14 Jan 2008 18:30:11 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Netcache+fields%2C+inputs%2C+and+event+types</link>
      <guid isPermaLink="false">3dda8837097357ffcdb02b8489237812</guid>
      <description>This add-on normalizes Netcache fields so that other Splunk applications understand them.</description>
    </item>
    <item>
      <title>iptables fields, inputs, and event types</title>
      <author>Splunk</author>
      <pubDate>Mon, 14 Jan 2008 18:22:47 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:iptables+fields%2C+inputs%2C+and+event+types</link>
      <guid isPermaLink="false">8e50a9451bd5816f9724fa6f991c34f5</guid>
      <description>This add-on applies to iptables firewall logs, normalizing their field names so they work well with other Splunk applications.</description>
    </item>
    <item>
      <title>Exchange fields and inputs</title>
      <author>Splunk</author>
      <pubDate>Mon, 14 Jan 2008 18:22:06 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Exchange+fields+and+inputs</link>
      <guid isPermaLink="false">c3c01540d9e1f1909b49230ea3661d5c</guid>
      <description>This add-on applies to Microsoft Exchange event tracking logs, bringing their field names into compliance with the Splunk interface standard (see http://www.splunkbase.com/howtos/Splunk/howto:Understanding_Splunk&#039;s_interface_standards).</description>
    </item>
    <item>
      <title>Sonicwall Firewall</title>
      <author>araitz</author>
      <pubDate>Wed, 19 Dec 2007 01:31:17 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Sonicwall+Firewall</link>
      <guid isPermaLink="false">744dc2c0b92faad8233e35bda951406b</guid>
      <description>This bundle performs field extractions for sonicwall TZ 170 without the UTM/IDS modules</description>
    </item>
    <item>
      <title>Common Event Format - Field Extractions</title>
      <author>raffy</author>
      <pubDate>Thu, 06 Dec 2007 02:11:28 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Common+Event+Format+-+Field+Extractions</link>
      <guid isPermaLink="false">e9265533eac559bd2aa0f535fcb64c09</guid>
      <description>CEF or the common event format is an event interoperability standard, defining a common syntax for communication among log generating devices and applications. This is an add-on to extract the fields of CEF messages.</description>
    </item>
    <item>
      <title>WebLogic Event Types</title>
      <author>Splunk</author>
      <pubDate>Tue, 06 Nov 2007 23:24:42 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:WebLogic+Event+Types</link>
      <guid isPermaLink="false">1ecc7a19fb8c03170fe6510af75727db</guid>
      <description>Field Extractions and Event Types that match events coming from WebLogic 9.2 and WebLogic 10.0.</description>
    </item>
    <item>
      <title>Postfix main.cf field extractions</title>
      <author>deeann</author>
      <pubDate>Thu, 18 Oct 2007 23:08:37 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Postfix+main.cf+field+extractions</link>
      <guid isPermaLink="false">21d2c0fe14ab80e15824e2d4fb820067</guid>
      <description>This Add-on extracts fields related to useful troubleshooting and configuration from the Postfix main.cf configuration file.</description>
    </item>
    <item>
      <title>Watchguard Firebox</title>
      <author>araitz</author>
      <pubDate>Fri, 12 Oct 2007 16:53:07 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Watchguard+Firebox</link>
      <guid isPermaLink="false">e2ee1fedc52b4d333682a90057c29666</guid>
      <description>Field Extractions for Watchguard Firebox</description>
    </item>
    <item>
      <title>WebLogic Access</title>
      <author>vly</author>
      <pubDate>Fri, 12 Oct 2007 06:51:05 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:WebLogic+Access</link>
      <guid isPermaLink="false">2fe0038ae954def137a22b7e57a06b98</guid>
      <description>Field Extractions for WebLogic HTTP Access Logs</description>
    </item>
    <item>
      <title>Checkpoint Event Field Extraction</title>
      <author>goldburtd</author>
      <pubDate>Tue, 09 Oct 2007 16:43:50 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Checkpoint+Event+Field+Extraction</link>
      <guid isPermaLink="false">2972347cfd6e27f50e215dc9c070df32</guid>
      <description>Search-time parsing of following fields:
loc, time, action, orig, i/f_dir, i/f_name, has_accounting, uuid, product, src, dst, proto, rule</description>
    </item>
    <item>
      <title>OSX Battery Monitor</title>
      <author>kordless</author>
      <pubDate>Mon, 08 Oct 2007 01:19:21 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:OSX+Battery+Monitor</link>
      <guid isPermaLink="false">d1dfec17085c80fbfb05090fd54a1548</guid>
      <description>Bundle for monitoring battery usage on an OSX based laptop.</description>
    </item>
    <item>
      <title>Brian&#039;s valgrind bundle</title>
      <author>BSplunk</author>
      <pubDate>Mon, 01 Oct 2007 17:05:39 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Brian%27s+valgrind+bundle</link>
      <guid isPermaLink="false">88d83453e8b02fdb2e84a491c7d25ab6</guid>
      <description>aggregates and extracts information from valgrind logs</description>
    </item>
    <item>
      <title>Brian&#039;s crash report log bundle</title>
      <author>BSplunk</author>
      <pubDate>Mon, 01 Oct 2007 17:05:18 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Brian%27s+crash+report+log+bundle</link>
      <guid isPermaLink="false">b294d9e6a2e0c4b062d18d02650f791e</guid>
      <description>Aggregates and extracts useful information from osx crash reporter logs.</description>
    </item>
    <item>
      <title>Snort fields</title>
      <author>mfratto</author>
      <pubDate>Mon, 01 Oct 2007 14:36:44 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Snort+fields</link>
      <guid isPermaLink="false">786e4729ca04060a32e4dee2ba912b4d</guid>
      <description>Extracts snort 2.6 fields which can be used in reporting.</description>
    </item>
    <item>
      <title>Nmap Scripted Input &amp; Field Extraction</title>
      <author>araitz</author>
      <pubDate>Fri, 28 Sep 2007 01:13:34 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Nmap+Scripted+Input+%26+Field+Extraction</link>
      <guid isPermaLink="false">94b5178420bfbcd37d4201914be5ac85</guid>
      <description>Want to put your Nmap output into Splunk?  

Check out this add-on, which will parse your grepable Nmap output into a scripted input and then perform some field extraction on the data.</description>
    </item>
    <item>
      <title>Nessus Bundle</title>
      <author>maverick</author>
      <pubDate>Fri, 07 Sep 2007 04:20:12 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Nessus+Bundle</link>
      <guid isPermaLink="false">761b6685ad2bb1f397ab50934bd0affe</guid>
      <description>This bundle extracts the common fields from a Nessus Vulnerability Scanner log file, such as the hostname, port, script id, and type.</description>
    </item>
    <item>
      <title>Negative Searching Demo Bundle</title>
      <author>maverick</author>
      <pubDate>Fri, 07 Sep 2007 04:18:53 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Negative+Searching+Demo+Bundle</link>
      <guid isPermaLink="false">5c0f7184d8c648bae1e1991d91f83aef</guid>
      <description>This bundle, created jointly by Maverick and Stephen Sorkin, demonstrates a way to perform negative searches by indexing known patterns and catching anomalous patterns into a separate index.</description>
    </item>
    <item>
      <title>Arkeia</title>
      <author>maverick</author>
      <pubDate>Fri, 07 Sep 2007 04:16:47 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Arkeia</link>
      <guid isPermaLink="false">3b217e3bda333d2eb467cb0dd83ad7ff</guid>
      <description>Arkeia Network Backup Bundle used to index the common fields from the backup log file to make searching and reporting easier.</description>
    </item>
    <item>
      <title>adds support for anonymizing log files at index time</title>
      <author>carasso</author>
      <pubDate>Mon, 20 Aug 2007 01:23:57 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:adds+support+for+anonymizing+log+files+at+index+time</link>
      <guid isPermaLink="false">68d72996a68ce809bc4d3c7b54916d9e</guid>
      <description>anonymizes ip address as 127.0.0.1 (localhost); 
email addresses as user@domain.com  ;                                                                                                                                                                        
social-security-numbers as 555-00-0000;
password/passwd looking values as &#039;password&#039;                                                                                                           ;
username/userid/login/user looking values as &#039;bob&#039;.</description>
    </item>
    <item>
      <title>Ironport field extractions</title>
      <author>ssorkin</author>
      <pubDate>Fri, 17 Aug 2007 20:07:35 +0000</pubDate>
      <link>http://www.splunkbase.com/apps/Fields/app:Ironport+field+extractions</link>
      <guid isPermaLink="false">54b9c491e0030048e9dc8718f26927d9</guid>
      <description>Provides file classification, date extraction, and extractions for ironport data.</description>
    </item>

  </channel>
</rss>