<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Eventgen - ERROR ExecProcessor - message from &amp;quot;python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py&amp;quot; in Security</title>
    <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481128#M15280</link>
    <description>&lt;P&gt;Hi all,&lt;BR /&gt;
For some reason i have this error in splunkd.log and there are no logs being generated from other applications which have eventgen.conf and samples dir. &lt;/P&gt;

&lt;P&gt;Did anyone now how to solve this problem. &lt;/P&gt;

&lt;P&gt;I suspect that this error is due to permissions but i checked all the permissions and everything is fine. &lt;/P&gt;

&lt;P&gt;Here is an more detailed example for the log: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;DEBUG    MainProcess {'event': 'Using cached earliest time: 2019-09-15 16:06:20.961619'}
09-15-2019 16:07:20.970 +0300 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py" 2019-09-15 16:07:20 eventgen        DEBUG    MainProcess {'event': "Flushing queue for sample 'nessus_singlehost.samples' with size 60"}

09-15-2019 16:27:24.664 +0300 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py" 2019-09-15 16:27:24 eventgen        DEBUG    MainProcess {'event': "Flushing queue for sample 'symantec_ep_scm_agent_act.samples' with size 2"}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks in advanced ! &lt;/P&gt;</description>
    <pubDate>Sun, 15 Sep 2019 13:30:29 GMT</pubDate>
    <dc:creator>astatrial</dc:creator>
    <dc:date>2019-09-15T13:30:29Z</dc:date>
    <item>
      <title>Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481128#M15280</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;
For some reason i have this error in splunkd.log and there are no logs being generated from other applications which have eventgen.conf and samples dir. &lt;/P&gt;

&lt;P&gt;Did anyone now how to solve this problem. &lt;/P&gt;

&lt;P&gt;I suspect that this error is due to permissions but i checked all the permissions and everything is fine. &lt;/P&gt;

&lt;P&gt;Here is an more detailed example for the log: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;DEBUG    MainProcess {'event': 'Using cached earliest time: 2019-09-15 16:06:20.961619'}
09-15-2019 16:07:20.970 +0300 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py" 2019-09-15 16:07:20 eventgen        DEBUG    MainProcess {'event': "Flushing queue for sample 'nessus_singlehost.samples' with size 60"}

09-15-2019 16:27:24.664 +0300 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py" 2019-09-15 16:27:24 eventgen        DEBUG    MainProcess {'event': "Flushing queue for sample 'symantec_ep_scm_agent_act.samples' with size 2"}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks in advanced ! &lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 13:30:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481128#M15280</guid>
      <dc:creator>astatrial</dc:creator>
      <dc:date>2019-09-15T13:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481129#M15281</link>
      <description>&lt;P&gt;Could you share your &lt;CODE&gt;eventgen.conf&lt;/CODE&gt; ?&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 13:34:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481129#M15281</guid>
      <dc:creator>lwu_splunk</dc:creator>
      <dc:date>2019-09-15T13:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481130#M15282</link>
      <description>&lt;P&gt;Of course: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# Copyright (C) 2005-2015 Splunk Inc. All Rights Reserved.
# DO NOT EDIT THIS FILE!
# Please make all changes to files in $SPLUNK_HOME/etc/apps/SA-Eventgen/local.
# To make changes, copy the section/stanza you want to change from $SPLUNK_HOME/etc/apps/SA-Eventgen/default
# into ../local and edit there.
#

## IMPORTANT! Do not specify any settings under a default stanza
## The layering system will not behave appropriately
## Use [global] instead
[default]

[global]
disabled = false
debug = false
verbosity = false
spoolDir = $SPLUNK_HOME/var/spool/splunk
spoolFile = &amp;lt;SAMPLE&amp;gt;
breaker = [^\r\n\s]+
mode = sample
sampletype = raw
interval = 60
delay = 0
timeMultiple = 1
count = -1
earliest = now
latest = now
randomizeEvents = false
outputMode = modinput
fileMaxBytes = 10485760
fileBackupFiles = 5
splunkPort = 8089
splunkMethod = https
index = main
source = eventgen
sourcetype = eventgen
host = 127.0.0.1
generator = default
rater = config
generatorWorkers = 1
outputWorkers = 1
timeField = _raw
threading = thread
profiler = false
maxIntervalsBeforeFlush = 3
maxQueueLength = 0
useOutputQueue = false
autotimestamps = [["\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2}:\\d{2}", "%Y-%m-%d %H:%M:%S"], ["\\d{1,2}\\/\\w{3}\\/\\d{4}\\s\\d{2}:\\d{2}:\\d{2}:\\d{1,3}", "%d/%b/%Y %H:%M:%S:%f"], ["\\d{4}-\\d{2}-\\d{2}T\\d{2}:\\d{2}:\\d{2}\\.\\d{3}", "%Y-%m-%dT%H:%M:%S.%f"], ["\\d{1,2}/\\w{3}/\\d{4}\\s\\d{2}:\\d{2}:\\d{2}:\\d{1,3}", "%d/%b/%Y %H:%M:%S:%f"], ["\\d{1,2}/\\d{2}/\\d{2}\\s\\d{1,2}:\\d{2}:\\d{2}", "%m/%d/%y %H:%M:%S"], ["\\d{2}-\\d{2}-\\d{4} \\d{2}:\\d{2}:\\d{2}", "%m-%d-%Y %H:%M:%S"], ["\\w{3} \\w{3} +\\d{1,2} \\d{2}:\\d{2}:\\d{2}", "%a %b %d %H:%M:%S"], ["\\w{3} \\w{3} \\d{2} \\d{4} \\d{2}:\\d{2}:\\d{2}", "%a %b %d %Y %H:%M:%S"], ["^(\\w{3}\\s+\\d{1,2}\\s\\d{2}:\\d{2}:\\d{2})", "%b %d %H:%M:%S"], ["(\\w{3}\\s+\\d{1,2}\\s\\d{1,2}:\\d{1,2}:\\d{1,2})", "%b %d %H:%M:%S"], ["(\\w{3}\\s\\d{1,2}\\s\\d{1,4}\\s\\d{1,2}:\\d{1,2}:\\d{1,2})", "%b %d %Y %H:%M:%S"], ["\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2}:\\d{2}\\.\\d{3}", "%Y-%m-%d %H:%M:%S.%f"], ["\\,\\d{2}\\/\\d{2}\\/\\d{2,4}\\s+\\d{2}:\\d{2}:\\d{2}\\s+[AaPp][Mm]\\,", ",%m/%d/%Y %I:%M:%S %p,"], ["^\\w{3}\\s+\\d{2}\\s+\\d{2}:\\d{2}:\\d{2}", "%b %d %H:%M:%S"], ["\\d{2}/\\d{2}/\\d{4} \\d{2}:\\d{2}:\\d{2}", "%m/%d/%Y %H:%M:%S"], ["^\\d{2}\\/\\d{2}\\/\\d{2,4}\\s+\\d{2}:\\d{2}:\\d{2}\\s+[AaPp][Mm]", "%m/%d/%Y %I:%M:%S %p"], ["\\d{2}\\/\\d{2}\\/\\d{4}\\s\\d{2}:\\d{2}:\\d{2}", "%m-%d-%Y %H:%M:%S"], ["\\\"timestamp\\\":\\s\\\"(\\d+)", "%s"], ["\\d{2}\\/\\w+\\/\\d{4}\\s\\d{2}:\\d{2}:\\d{2}:\\d{3}", "%d-%b-%Y %H:%M:%S:%f"], ["\\\"created\\\":\\s(\\d+)", "%s"], ["\\d{4}-\\d{2}-\\d{2}T\\d{2}:\\d{2}:\\d{2}", "%Y-%m-%dT%H:%M:%S"], ["\\d{1,2}/\\w{3}/\\d{4}:\\d{2}:\\d{2}:\\d{2}:\\d{1,3}", "%d/%b/%Y:%H:%M:%S:%f"], ["\\d{1,2}/\\w{3}/\\d{4}:\\d{2}:\\d{2}:\\d{2}", "%d/%b/%Y:%H:%M:%S"]]
autotimestamp = false
httpeventWaitResponse = true
disableLoggingQueue = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This is the default eventgen.conf of the eventgen app. &lt;/P&gt;

&lt;P&gt;The symantec eventgen.conf is also the one shipped with the add on. &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 13:39:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481130#M15282</guid>
      <dc:creator>astatrial</dc:creator>
      <dc:date>2019-09-15T13:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481131#M15283</link>
      <description>&lt;P&gt;I mean the eventgen.conf in your symantec app. &lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 13:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481131#M15283</guid>
      <dc:creator>lwu_splunk</dc:creator>
      <dc:date>2019-09-15T13:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481132#M15284</link>
      <description>&lt;P&gt;It is a really long file, it is the default of the "Splunk_TA_symantec-ep".&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:11:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481132#M15284</guid>
      <dc:creator>astatrial</dc:creator>
      <dc:date>2020-09-30T02:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481133#M15285</link>
      <description>&lt;P&gt;Actually the error msg above is &lt;CODE&gt;DEBUG&lt;/CODE&gt; msg. I could not see any ERROR from the log. I have checked with the &lt;CODE&gt;eventgen.conf&lt;/CODE&gt; in &lt;CODE&gt;Splunk_TA_symantec-ep&lt;/CODE&gt;. Seems every config is fine to generate the data. Could you change the time  range in Splunk search and check the events?&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 14:13:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481133#M15285</guid>
      <dc:creator>lwu_splunk</dc:creator>
      <dc:date>2019-09-15T14:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481134#M15286</link>
      <description>&lt;P&gt;It seems by default all the stanzas in &lt;CODE&gt;eventgen.conf&lt;/CODE&gt; in app &lt;CODE&gt;Splunk_TA_symantec-ep&lt;/CODE&gt; are disabled. You should manually enable them. Change &lt;CODE&gt;disabled = 1&lt;/CODE&gt; to &lt;CODE&gt;disabled = 0&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 14:17:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481134#M15286</guid>
      <dc:creator>lwu_splunk</dc:creator>
      <dc:date>2019-09-15T14:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481135#M15287</link>
      <description>&lt;P&gt;If you will look closely, there is "ERROR ExecProcessor". &lt;BR /&gt;
There is disabled=1 for specific stanzas. &lt;BR /&gt;
I did the same process on another machine without any further configurations and it worked fine. &lt;BR /&gt;
In addition the problem is not just with symantec, but with every other app with eventget.conf&lt;/P&gt;

&lt;P&gt;I just need to fix this in the other machine (it is not an option to replace it). &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 14:39:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481135#M15287</guid>
      <dc:creator>astatrial</dc:creator>
      <dc:date>2019-09-15T14:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481136#M15288</link>
      <description>&lt;P&gt;The &lt;CODE&gt;ERROR ExecProcessor&lt;/CODE&gt; is misleading that we need to fix for Eventgen. But it is not error log actually.  &lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 21:57:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481136#M15288</guid>
      <dc:creator>lwu_splunk</dc:creator>
      <dc:date>2019-09-15T21:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481137#M15289</link>
      <description>&lt;P&gt;So do you know what may be the reason that eventgen can't generate events from other apps files ? &lt;/P&gt;

&lt;P&gt;On the other machine that works fine i don't get those logs. &lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 07:29:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481137#M15289</guid>
      <dc:creator>astatrial</dc:creator>
      <dc:date>2019-09-16T07:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481138#M15290</link>
      <description>&lt;P&gt;I am not sure since there is not enough info for me.  A few key points:&lt;BR /&gt;
1. Make sure the &lt;CODE&gt;symantec&lt;/CODE&gt; add-on has permission. &lt;A href="http://splunk.github.io/eventgen/SETUP.html"&gt;http://splunk.github.io/eventgen/SETUP.html&lt;/A&gt;&lt;BR /&gt;
2. Make sure the Eventgen modular input is enabled;&lt;BR /&gt;
3. Search in Splunk with all time filter;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 07:34:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481138#M15290</guid>
      <dc:creator>lwu_splunk</dc:creator>
      <dc:date>2019-09-16T07:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481139#M15291</link>
      <description>&lt;P&gt;I want to correct myself. &lt;BR /&gt;
I get the same logs on the machine that it does work on. &lt;BR /&gt;
So the reason is apparently something else. &lt;BR /&gt;
But i still can't seem to find the problem. &lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 14:02:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481139#M15291</guid>
      <dc:creator>astatrial</dc:creator>
      <dc:date>2019-09-16T14:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen - ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/SA-Eventgen/bin/modinput_eventgen.py"</title>
      <link>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481140#M15292</link>
      <description>&lt;P&gt;I can schedule a short meeting with you. Send  your available time to me: &lt;CODE&gt;lwu@splunk.com&lt;/CODE&gt;.&lt;BR /&gt;
(I am on GMT+8 timezone)&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 01:01:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Eventgen-ERROR-ExecProcessor-message-from-quot-python-opt-splunk/m-p/481140#M15292</guid>
      <dc:creator>lwu_splunk</dc:creator>
      <dc:date>2019-09-17T01:01:59Z</dc:date>
    </item>
  </channel>
</rss>

