<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic generate dummy data -eventgen in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454849#M95023</link>
    <description>&lt;P&gt;Hello&lt;BR /&gt;
Can you provide some working solution for eventgen with testdata and eventgen.conf which is working for you?&lt;/P&gt;

&lt;P&gt;I am 0 interested in how it is working or their docs as I've used hours to try make it working without success so I just need someone who has already working set of conf with some simple sample data.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2019 10:48:36 GMT</pubDate>
    <dc:creator>net1993</dc:creator>
    <dc:date>2019-07-02T10:48:36Z</dc:date>
    <item>
      <title>generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454849#M95023</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;
Can you provide some working solution for eventgen with testdata and eventgen.conf which is working for you?&lt;/P&gt;

&lt;P&gt;I am 0 interested in how it is working or their docs as I've used hours to try make it working without success so I just need someone who has already working set of conf with some simple sample data.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 10:48:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454849#M95023</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-07-02T10:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454850#M95024</link>
      <description>&lt;P&gt;you can download the eventgen app and look in its own docs.&lt;BR /&gt;
also, many TAs has sample data and eventgen.conf in them, turning eventgen on alongside with the TA will generate fake data.&lt;BR /&gt;
explore the evengen.conf in the to further understand how it works&lt;BR /&gt;
try and download this TA for Cisco ASA: &lt;A href="https://splunkbase.splunk.com/app/1620/"&gt;https://splunkbase.splunk.com/app/1620/&lt;/A&gt;&lt;BR /&gt;
it supposed to have eventgen.conf in it&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 12:50:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454850#M95024</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-07-02T12:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454851#M95025</link>
      <description>&lt;P&gt;Hi. &lt;BR /&gt;
I dont need to see how eventgen its working, I need a working config file and data sample so I can just run and not lose time with that simple thing.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 06:31:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454851#M95025</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-07-03T06:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454852#M95026</link>
      <description>&lt;P&gt;There are officially two versions to run eventgen&lt;BR /&gt;
1. as a python package (needs pypy etc)&lt;BR /&gt;
2. As a Splunk app. Be cautious that this is NOT accidently pushed to PROD&lt;/P&gt;

&lt;P&gt;I'm not a big fan of both above, as I need it to be run as a standalone softare. Below are some hints..&lt;/P&gt;

&lt;P&gt;Are you using the old eventgen or the new eventgen? &lt;BR /&gt;
The old eventgen had a youtube video: &lt;A href="https://www.youtube.com/watch?v=wLYMY9dwBXI"&gt;https://www.youtube.com/watch?v=wLYMY9dwBXI&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;For the new eventgen, if you want to simulate similar fashion, you need to extract the SA-Eventgen/lib/splunk_eventgen . and do as above. When I get time, I will post this as step by step process into a blog.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 08:43:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454852#M95026</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2019-07-03T08:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454853#M95027</link>
      <description>&lt;P&gt;I got last version. of eventgen&lt;BR /&gt;
I work on TEST machine:)&lt;BR /&gt;
It will be great if you create a guide for this. I tried yesterday but it simply doesnt insert data in splunk.&lt;BR /&gt;
I can see that it generate more data in my sample file but nothing more, it doesnt send data to splunk.&lt;BR /&gt;
I will try this with extract of splunk_gen&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 08:47:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454853#M95027</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-07-03T08:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454854#M95028</link>
      <description>&lt;P&gt;yes, the working config file is within the TA,go to the default directory and look for eventgen.conf&lt;BR /&gt;
here is the content of the file from that TA version 3.2.5&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;################
####   ASA  ####
################

[samplelog.cisco.asa]
sourcetype=cisco:asa
interval = 150
earliest = -60m
latest = now

##replace timestamp
token.0.token = ^(\w{3}\s+\d{1,2}\s+\d{1,2}:\d{1,2}:\d{1,2})
token.0.replacementType = timestamp
token.0.replacement = %b %d %H:%M:%S

##replace timestamp 2
token.1.token = ^(\d{4}\-\d{2}\-\d{2}\s+\d{1,2}:\d{1,2}:\d{1,2})
token.1.replacementType = timestamp
token.1.replacement = %Y-%m-%d %H:%M:%S

##replace timestamp 3
token.2.token = ^(\w{3}\s\d{1,2}\s\d{1,4}\s\d{1,2}:\d{1,2}:\d{1,2})
token.2.replacementType = timestamp
token.2.replacement = %b %d %Y %H:%M:%S

##repalce user
token.3.token = (UUUUUUUU)
token.3.replacementType = file
token.3.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\userName.sample

##replace local address
token.4.token = \sladdr\s(XXX\.XXX\.XXX\.XXX)
token.4.replacementType = file
token.4.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\internal_ips.sample

##replace foreign address
token.5.token = \sfaddr\s(XXX\.XXX\.XXX\.XXX)
token.5.replacementType = random
token.5.replacement = ipv4

##replace outside ips
token.6.token = (?:O|o)utside\S*(?::|/)(XXX\.XXX\.XXX\.XXX)
token.6.replacementType = random
token.6.replacement = ipv4

##replace inside ips
token.7.token = (?:I|i)nside\S*(?::|/)(XXX\.XXX\.XXX\.XXX)
token.7.replacementType = file
token.7.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\internal_ips.sample

##replace username part of email
token.8.token = YYYYYYYYYY
token.8.replacementType = file
token.8.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\userName.sample

##replacing remaining ip
token.9.token = XXX\.XXX\.XXX\.XXX
token.9.replacementType = random
token.9.replacement = ipv4

##replacing Hostname
token.10.token = (HHHHHHHH)
token.10.replacementType = file
token.10.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\hostname.sample

##replacing ipv6
token.11.token = VVVVVVVVVV
token.11.replacementType = random
token.11.replacement = ipv6

##replacing internal IP
token.12.token = (##INTERNAL_IP##)
token.12.replacementType = file
token.12.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\internal_ips.sample

##replacing IPv6
token.13.token = (##IP_V6##)
token.13.replacementType = random
token.13.replacement = ipv6

################
####  FWSM  ####
################

[samplelog.cisco.fwsm]
sourcetype=cisco:fwsm
interval = 150
earliest = -60m
latest = now

#replace timestamp 1
token.0.token = ^(\w{3}\s+\d{1,2}\s\d{1,2}:\d{1,2}:\d{1,2})
token.0.replacementType = timestamp
token.0.replacement = %b %d %H:%M:%S

##replace timestamp 2
token.1.token = ^(\w{3}\s\d{1,2}\s\d{1,4}\s\d{1,2}:\d{1,2}:\d{1,2})
token.1.replacementType = timestamp
token.1.replacement = %b %d %Y %H:%M:%S

##replace user
token.2.token = (UUUUUUUU)
token.2.replacementType = file
token.2.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\userName.sample

##replace local address
token.3.token = \sladdr\s(XXX\.XXX\.XXX\.XXX)
token.3.replacementType = file
token.3.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\internal_ips.sample

##replace foreign address
token.4.token = \sfaddr\s(XXX\.XXX\.XXX\.XXX)
token.4.replacementType = random
token.4.replacement = ipv4

##replace outside ips
token.5.token = (?:O|o)utside\S*(?::|/)(XXX\.XXX\.XXX\.XXX)
token.5.replacementType = random
token.5.replacement = ipv4

##replace inside ips
token.6.token = (?:I|i)nside\S*(?::|/)(XXX\.XXX\.XXX\.XXX)
token.6.replacementType = file
token.6.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\internal_ips.sample

##replacing remaining ip
token.7.token = XXX\.XXX\.XXX\.XXX
token.7.replacementType = random
token.7.replacement = ipv4

##replacing Hostname
token.8.token = (HHHHHHHH)
token.8.replacementType = file
token.8.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\hostname.sample

################
####   PIX  ####
################

[samplelog.cisco.pix]
sourcetype=cisco:pix
interval = 150
earliest = -60m
latest = now

#replace timestamp 1
token.0.token = ^(\w{3}\s+\d{1,2}\s\d{1,2}:\d{1,2}:\d{1,2})
token.0.replacementType = timestamp
token.0.replacement = %b %d %H:%M:%S

##replace timestamp 2
token.1.token = ^(\w{3}\s\d{1,2}\s\d{1,4}\s\d{1,2}:\d{1,2}:\d{1,2})
token.1.replacementType = timestamp
token.1.replacement = %b %d %Y %H:%M:%S

##replace user
token.2.token = (UUUUUUUU)
token.2.replacementType = file
token.2.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\userName.sample

##replace outside ips
token.3.token = outside\s?:\s?(?:Allocated ip = )?(XXX\.XXX\.XXX\.XXX)
token.3.replacementType = random
token.3.replacement = ipv4

##replace inside ips
token.4.token = inside\s?:\s?(?:.*\()?(XXX\.XXX\.XXX\.XXX)
token.4.replacementType = file
token.4.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\internal_ips.sample

##replacing remaining ip
token.5.token = XXX\.XXX\.XXX\.XXX
token.5.replacementType = random
token.5.replacement = ipv4

##replacing Hostname
token.6.token = (HHHHHHHH)
token.6.replacementType = file
token.6.replacement = $SPLUNK_HOME\etc\apps\Splunk_TA_cisco-asa\samples\hostname.sample
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 03 Jul 2019 10:39:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454854#M95028</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-07-03T10:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454855#M95029</link>
      <description>&lt;P&gt;Thanks. I will try it and response if ok.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 10:41:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454855#M95029</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-07-03T10:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454856#M95030</link>
      <description>&lt;P&gt;if you take a copy of splunk_eventgen into say a temporary directory and the jinja2/markupsafe&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cp -r SA-Eventgen/lib/splunk_eventgen /tmp/
cp -r SA-Eventgen/lib/markupsafe /tmp/splunk_eventgen/lib/
cp -r SA-Eventgen/lib/jinja2 /tmp/splunk_eventgen/lib/
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Copy one of the sample tutorial config to your name &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cp /tmp/splunk_eventgen/README/eventgen.conf.tutorial1 /tmp/splunk_eventgen/README/mytest.tutorial
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Validate the &lt;CODE&gt;mytest.tutorial file&lt;/CODE&gt; and ensure it has . (comment out all outputMode other than &lt;CODE&gt;splunkstream&lt;/CODE&gt;)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;outputMode=splunkstream
splunkHost = localhost
splunkUser = &amp;lt;your_admin_user&amp;gt;
splunkPass = &amp;lt;your_admin_passwd&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;rest should remain the same. &lt;/P&gt;

&lt;P&gt;then&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cd /tmp/splunk_eventgen
/opt/splunk/bin/splunk cmd python __main_.py generate README/mytest.tutorial
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will pump the sample data directly into Splunk&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 11:43:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454856#M95030</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2019-07-03T11:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454857#M95031</link>
      <description>&lt;P&gt;@adonio, I see only ver. 3.4.0 in splunk base and cannot find older realeses. In the one I get, there is not eventconf.conf neither sample data.&lt;BR /&gt;
I guess, I can use eventconf.conf with content which you have post above but I don't have the sample data. Can you provide sample data?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 11:41:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454857#M95031</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-07-05T11:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454858#M95032</link>
      <description>&lt;P&gt;Thank you, sir for your answer. But, i still confuse about different outputMode in Eventgen.&lt;/P&gt;

&lt;P&gt;What is the point of using different outputMode in Eventgen ?&lt;/P&gt;

&lt;P&gt;Because when i use the same sample log for different outputMode like tcpout and udpout. Both, will get the same result. Even, i cannot identify which one from tcpout or udpout.&lt;/P&gt;

&lt;P&gt;At documentation ( &lt;A href="https://splunk.github.io/eventgen/REFERENCE.html"&gt;https://splunk.github.io/eventgen/REFERENCE.html&lt;/A&gt; ), every outputMode should have different &lt;STRONG&gt;MUST HAVE&lt;/STRONG&gt; configuration. In your example, when using splunkstream. You must have splunkHost, splunkUser, and splunkPass configuration.&lt;/P&gt;

&lt;P&gt;When i use httpevent outputMode, i also set httpeventServers too. In httpeventServers, i also include valid token. And it works. But, when i use wrong token, it still works too. What's going on here ?&lt;/P&gt;

&lt;P&gt;Is it supposed behavior that EventGen do ?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2020 02:54:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454858#M95032</guid>
      <dc:creator>rendi7936</dc:creator>
      <dc:date>2020-01-06T02:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454859#M95033</link>
      <description>&lt;P&gt;it depends on how you want to get the data into Splunk.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;outputMode = modinput | s2s | file | splunkstream | stdout | devnull | spool | httpevent | syslogout | tcpout | udpout | metric_httpevent
    * Specifies how to output log data. Modinput is default.
    * If setting spool, should set spoolDir
    * If setting file, should set fileName
    * If setting splunkstream, should set splunkHost, splunkPort, splunkMethod,
      splunkUser and splunkPassword if not Splunk embedded
    * If setting s2s, should set splunkHost and splunkPort
    * If setting syslogout, should set syslogDestinationHost and syslogDestinationPort
    * If setting httpevent, should set httpeventServers
    * If setting metric_httpevent, should set httpeventServers and make sure your index is a splunk metric index
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;essentially, the simplified settings would be (in my experience)&lt;BR /&gt;
1. use &lt;CODE&gt;splunkstream&lt;/CODE&gt; if you want to stream data directly into Splunk. Good for DEV systems&lt;BR /&gt;
2. use &lt;CODE&gt;file&lt;/CODE&gt; if you want to output into a file and then use inputs.conf to read it. Good for remote/clustered systems&lt;BR /&gt;
3. use &lt;CODE&gt;syslogout&lt;/CODE&gt; if you want to integrate with syslog&lt;/P&gt;

&lt;P&gt;Rest of settings are rarely used. Try one of the above and see if it works (baby steps). Then once working, you can extend it to complex output types.&lt;/P&gt;

&lt;P&gt;regarding your query about httpevent, ensure below settings are in place.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;httpeventServers = 
    * valid json that contains a list of server objects
    * valid server objects contain a protocol, a address, a port and a session key
    * {"servers":[{ "protocol":"https", "address":"127.0.0.1", "port":"8088", "key":"12345-12345-123123123123123123"}]}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When you say wrong token, do you mean a separate "key" ?  (Please beware that &lt;CODE&gt;accessToken&lt;/CODE&gt;  is &lt;STRONG&gt;NOT&lt;/STRONG&gt; for httpevent)&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 10:35:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454859#M95033</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2020-01-10T10:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454860#M95034</link>
      <description>&lt;P&gt;I agree, the docs hosted at &lt;A href="http://splunk.github.io/eventgen/"&gt;http://splunk.github.io/eventgen/&lt;/A&gt; are incredibly confusing for first-timers.&lt;/P&gt;

&lt;P&gt;They don't make clear a simple fact, for example, that you need a combination of event templates and files containing rotating values (users, hosts, etc) in order to get the tool running. You have to find the templates based on real log strings or build your own. &lt;CODE&gt;local/eventgen.conf&lt;/CODE&gt; stores this combined config. Everything else is secondary.&lt;/P&gt;

&lt;P&gt;rav3n's &lt;STRONG&gt;Splunk EventGen — Quick Tutorial&lt;/STRONG&gt; on Medium helped me to get started and to wrap my head around how eventgen works. Check it out here: &lt;A href="https://medium.com/@rav3n/splunk-eventgen-quick-tutorial-593f526bafc1"&gt;https://medium.com/@rav3n/splunk-eventgen-quick-tutorial-593f526bafc1&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2020 18:42:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/454860#M95034</guid>
      <dc:creator>ag0x00</dc:creator>
      <dc:date>2020-05-01T18:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: generate dummy data -eventgen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/695907#M115514</link>
      <description>&lt;P&gt;I'm not normally one to resurrect dead posts, but as I was myself trying to accomplish the same task and via Google found this post, figured I'd give an update.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Per the documentation for the TA (&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/CiscoASA/Releasehistory)" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/CiscoASA/Releasehistory)&lt;/A&gt;&amp;nbsp;they removed the eventgen support in version 3.2.5&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TheLawsOfChaos_0-1723348695466.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32161i7F4E71D73C849019/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TheLawsOfChaos_0-1723348695466.png" alt="TheLawsOfChaos_0-1723348695466.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Aug 2024 03:59:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/generate-dummy-data-eventgen/m-p/695907#M115514</guid>
      <dc:creator>TheLawsOfChaos</dc:creator>
      <dc:date>2024-08-11T03:59:03Z</dc:date>
    </item>
  </channel>
</rss>

