Skip to content

Repository files navigation

Splunkbase App URL Skill

A Claude Skill for fetching the latest download URLs from Splunkbase applications. This skill is particularly useful when creating Docker Compose configurations for Splunk deployments.

Overview

This skill enables Claude to:

  • Fetch the latest release download URL for any Splunkbase app by ID
  • Generate comma-separated URLs for multiple apps
  • Create properly formatted SPLUNK_APPS_URL environment variables
  • Integrate seamlessly with Docker Compose configurations

Installation

As a Claude Skill

  1. Download the splunkbase-skill.zip file from the latest GitHub release
  2. Follow the instructions: Using Skills in Claude
  3. Extract and import the skill in your Claude workspace

Python Implementation

Requirements

pip install requests

Usage

fromsplunkbase_urlsimportget_splunkbase_app_url, get_multiple_splunkbase_urls# Single appurl=get_splunkbase_app_url("4353")
print(url)
# Output: https://splunkbase.splunk.com/app/4353/release/1.8.20/download/# Multiple appsurls=get_multiple_splunkbase_urls(["4353", "7931"])
print(urls)
# Output: https://splunkbase.splunk.com/app/4353/release/1.8.20/download/,https://splunkbase.splunk.com/app/7931/release/0.2.6/download/

Bash Script

Bash Setup

  • curl
  • jq (install with brew install jq on macOS or apt-get install jq on Linux)

Bash Installationation

Make the script executable:

chmod +x get_splunkbase_urls.sh

Bash Examples

# Single app
./get_splunkbase_urls.sh 4353
# Multiple apps
./get_splunkbase_urls.sh 4353 7931 1876 833
# Verbose output with app details
./get_splunkbase_urls.sh -v 4353 7931
# Use in Docker Compose generation
SPLUNK_APPS_URL=$(./get_splunkbase_urls.sh 4353 7931)echo"SPLUNK_APPS_URL: $SPLUNK_APPS_URL"# Use in environment file (.env)echo"SPLUNK_APPS_URL=$(./get_splunkbase_urls.sh 4353 7931)">> .env

Features

  • Multiple app support: Fetch URLs for one or more apps at once
  • Verbose mode: Display app names, versions, and URLs with -v flag
  • Error handling: Graceful error handling with meaningful error messages
  • Dependency check: Validates curl and jq are installed
  • Input validation: Ensures app IDs are numeric
  • Docker Compose ready: Output format compatible with SPLUNK_APPS_URL environment variable

Examples

Example 1: Fetch Single App URL

Request to Claude:

Get me the latest download URL for Splunkbase app 4353

Claude Response:

App: Config Explorer
Version: 1.8.21
Download URL: https://splunkbase.splunk.com/app/4353/release/1.8.21/download/
This is the current latest release. If you need this for a Docker Compose SPLUNK_APPS_URL environment variable, you can use the URL directly.

Example 2: Generate Docker Compose Configuration

Request to Claude:

Create a Docker Compose service for Splunk with apps 4353 and 7931.

Claude Response:

services:
splunk:
hostname: splunkcontainer_name: splunkimage: splunk/splunk:latestplatform: linux/amd64environment:
SPLUNK_GENERAL_TERMS: --accept-sgt-current-at-splunk-comSPLUNK_START_ARGS: --accept-licenseSPLUNK_PASSWORD: ${SPLUNK_PASSWORD}SPLUNKBASE_USERNAME: ${SPLUNKBASE_USER}@splunk.comSPLUNKBASE_PASSWORD: ${SPLUNKBASE_PASS}SPLUNK_APPS_URL: https://splunkbase.splunk.com/app/4353/release/1.8.20/download/,https://splunkbase.splunk.com/app/7931/release/0.2.6/download/TZ: ${TZ:-Europe/Brussels}volumes:
- ./default.yml:/tmp/defaults/default.yml
- splunk-var:/opt/splunk/var
- splunk-etc:/opt/splunk/etcports:
- "8000:8000"
- "8089:8089"networks:
- splunkrestart: alwaysvolumes:
splunk-var:
splunk-etc:
networks:
splunk:

Example 3: Update Existing Docker Compose

Request to Claude:

Update my SPLUNK_APPS_URL with the latest versions of apps 4353 and 7931.

Claude Response:

SPLUNK_APPS_URL: https://splunkbase.splunk.com/app/4353/release/1.8.20/download/,https://splunkbase.splunk.com/app/7931/release/0.2.6/download/

API Details

Splunkbase API Endpoint

https://splunkbase.splunk.com/api/v1/app/{app_id}/release

Response Format

[
{
"name": "1.8.20",
"title": "Version 1.8.20",
"created_time": "2024-01-15T10:30:00Z",
"published": true
}
]

The first element contains the latest release information.

Common Splunkbase Apps

App IDNameDescription
4353Splunk Add-on for Cisco ISECisco Identity Services Engine integration
1809Splunk Add-on for WindowsWindows event log collection
742Splunk Add-on for Unix and LinuxUnix/Linux system monitoring
3212Splunk Add-on for AWSAmazon Web Services integration
1621Splunk Add-on for Microsoft Cloud ServicesMicrosoft 365 and Azure integration

Troubleshooting

Issue: "Error fetching details for Splunkbase app"

Cause: Invalid app ID or network connectivity issue

Solution:

  1. Verify the app ID by visiting https://splunkbase.splunk.com/app/{app_id}/
  2. Check your internet connection
  3. Ensure the Splunkbase API is accessible

Issue: "Unexpected response structure"

Cause: The app may not have any releases or the API response changed

Solution:

  1. Check if the app exists on Splunkbase
  2. Verify the app has published releases
  3. Update the script to handle the new API format

Issue: jq not found (Bash script)

Cause:jq is not installed

Solution:

# macOS
brew install jq
# Ubuntu/Debian
sudo apt-get install jq
# CentOS/RHEL
sudo yum install jq

Security Best Practices

  1. Never hardcode credentials in Docker Compose files

  2. Use environment variables for sensitive data:

    # .env file
    SPLUNK_PASSWORD=your_password
    SPLUNKBASE_USER=your_username
    SPLUNKBASE_PASS=your_splunkbase_password
  3. Add .env to .gitignore

  4. Use secrets management for production deployments

Contributing

To improve this skill:

  1. Test with various Splunkbase apps
  2. Add error handling for edge cases
  3. Extend with caching for frequently accessed apps
  4. Add support for specific version fetching (not just latest)

License

This skill is provided as-is for use with Claude and Splunk deployments.

Version

  • v1.1.0 - Enhanced features and improvements (2025-11-27)
  • v1.0.0 - Initial release (2025-11-27)

About

A Claude Skill for fetching the latest download URLs from Splunkbase applications. This skill is particularly useful when creating Docker Compose configurations for Splunk deployments.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages