<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Eventgen not taking my txt file from sample directory in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Eventgen-not-taking-my-txt-file-from-sample-directory/m-p/527413#M9429</link>
    <description>&lt;P&gt;&lt;SPAN&gt;yes several times, and checked the enabled status also the sharing is Global&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 31 Oct 2020 11:48:32 GMT</pubDate>
    <dc:creator>Nith</dc:creator>
    <dc:date>2020-10-31T11:48:32Z</dc:date>
    <item>
      <title>Eventgen not taking my txt file from sample directory</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Eventgen-not-taking-my-txt-file-from-sample-directory/m-p/527337#M9425</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I've added a txt file to SA-Eventgen sample folder and wrote the configuration in the eventgen.conf file as follows.&lt;/P&gt;&lt;P&gt;[mihealth-https_error]&lt;BR /&gt;mode = sample&lt;BR /&gt;interval = 15&lt;BR /&gt;earliest = -15s&lt;BR /&gt;latest = now&lt;BR /&gt;count = 25&lt;BR /&gt;hourOfdayRate = { "0": 0.8, "1": 1.0: "2": 0.9, "3":0.7, "4":0.7, "5":0.7, "6":0.7, "7":0.7, "8":0.7, "9":0.7, "10":0.7, "11":0.7, "12":0.7, "13":0.7, "14":0.7, "15":0.7, "16":0.7, "17":0.7, "18":0.7, "19":0.7, "20":0.7, "21":0.7, "22":0.7, "23":0.7 }&lt;BR /&gt;dayOfWeekRate = { "0": 0.7, "1": 0.7, "2": 0.7, "3": 0.6, "4": 0.8, "5": 1.0, "6": 0.9 }&lt;BR /&gt;randomizeCount = 0.2&lt;BR /&gt;randomizeEvents = true&lt;BR /&gt;outputMode = modinput&lt;BR /&gt;sourcetype = eventgen_test3&lt;BR /&gt;source = eventgendemo3&lt;BR /&gt;index = eventgen&lt;BR /&gt;token.0.token = \[(\w+\s\w+\s\d+\s\d+:\d+:\d+.\d+\s\d+)\]&lt;BR /&gt;token.0.replacementType = timestamp&lt;BR /&gt;token.0.replacement = %a %b %d %H:%M:%S.%6N %Y&lt;BR /&gt;token.1.token = \(\w+\s\w+.(\w+).\w+:\d+\)&lt;BR /&gt;token.1.replacementType = file&lt;BR /&gt;token.1.replacement = $SPLUNK_HOME/etc/apps/SA-Eventgen/samples/orderType.sample&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the txt data look like this in the sample folder:&lt;/P&gt;&lt;P&gt;[Thu Jun 04 09:37:31.838874 2020] [ssl:info] [pid 24583] [client 10.10.10.1:39900] NC00000: Connection to child 8 established (server core.Company.com:443)&lt;/P&gt;&lt;P&gt;it is not generating any events, could you please help me?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 16:34:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Eventgen-not-taking-my-txt-file-from-sample-directory/m-p/527337#M9425</guid>
      <dc:creator>Nith</dc:creator>
      <dc:date>2020-10-30T16:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen not taking my txt file from sample directory</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Eventgen-not-taking-my-txt-file-from-sample-directory/m-p/527355#M9426</link>
      <description>&lt;P&gt;Dumb question: did you restart Splunk after changing eventgen.conf?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 18:01:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Eventgen-not-taking-my-txt-file-from-sample-directory/m-p/527355#M9426</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-10-30T18:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Eventgen not taking my txt file from sample directory</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Eventgen-not-taking-my-txt-file-from-sample-directory/m-p/527413#M9429</link>
      <description>&lt;P&gt;&lt;SPAN&gt;yes several times, and checked the enabled status also the sharing is Global&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Oct 2020 11:48:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Eventgen-not-taking-my-txt-file-from-sample-directory/m-p/527413#M9429</guid>
      <dc:creator>Nith</dc:creator>
      <dc:date>2020-10-31T11:48:32Z</dc:date>
    </item>
  </channel>
</rss>

