<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SA-Eventgen and Splunk SPL Examples - Help Generating Data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/SA-Eventgen-and-Splunk-SPL-Examples-Help-Generating-Data/m-p/479398#M134368</link>
    <description>&lt;P&gt;Here is the latest documentation for Eventgen: &lt;A href="http://splunk.github.io/eventgen/"&gt;http://splunk.github.io/eventgen/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Sep 2019 22:32:46 GMT</pubDate>
    <dc:creator>lwu_splunk</dc:creator>
    <dc:date>2019-09-10T22:32:46Z</dc:date>
    <item>
      <title>SA-Eventgen and Splunk SPL Examples - Help Generating Data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SA-Eventgen-and-Splunk-SPL-Examples-Help-Generating-Data/m-p/479397#M134367</link>
      <description>&lt;P&gt;Hello community, I've installed SA-Eventgen and SPL Examples as directed in the following .conf talk:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://conf.splunk.com/files/2017/recordings/creating-your-own-splunk-learning-environment.mp4" target="_blank"&gt;https://conf.splunk.com/files/2017/recordings/creating-your-own-splunk-learning-environment.mp4&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;However, this doesn't work. I've taken a look at the documentation, created a folder named "local" under the SPL_Examples directory and moved the eventgen.config from the apps\spl_examples\default folder to the apps\spl_exampels\local  folder. I restarted Splunk and still getting no events. What am I missing?  Luke Netto's talk referenced above makes it seem so trivial? &lt;/P&gt;

&lt;P&gt;I'm working with a brand new install of Splunk on a Windows 10 system. The only apps I've installed as of this post are SA-Eventgen and SPL Examples. &lt;/P&gt;

&lt;P&gt;Splunk Enterprise Version: 7.3.1&lt;BR /&gt;
SA-Eventgen Version: 6.5.1&lt;BR /&gt;
Splunk SPL Examples Version: 1.0.0&lt;/P&gt;

&lt;P&gt;Appreciate any help with this!&lt;/P&gt;

&lt;P&gt;Here are some of the errors I'm seeing in the internal index:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/274695-mainprocesstokenerror.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;From Splunkd.log: &lt;/P&gt;

&lt;P&gt;09-11-2019 12:21:10.206 -0500 ERROR ExecProcessor - message from "python "C:\Program Files\Splunk\etc\apps\SA-Eventgen\bin\modinput_eventgen.py"" 2019-09-11 12:21:10 eventgen        WARNING  MainProcess {'positional_args': (0,), 'event': 'Generator Queue Full. Reput the backfill generator task later. %d backfill generators are dispatched.'}&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:10:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SA-Eventgen-and-Splunk-SPL-Examples-Help-Generating-Data/m-p/479397#M134367</guid>
      <dc:creator>dillardo_2</dc:creator>
      <dc:date>2020-09-30T02:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: SA-Eventgen and Splunk SPL Examples - Help Generating Data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SA-Eventgen-and-Splunk-SPL-Examples-Help-Generating-Data/m-p/479398#M134368</link>
      <description>&lt;P&gt;Here is the latest documentation for Eventgen: &lt;A href="http://splunk.github.io/eventgen/"&gt;http://splunk.github.io/eventgen/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 22:32:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SA-Eventgen-and-Splunk-SPL-Examples-Help-Generating-Data/m-p/479398#M134368</guid>
      <dc:creator>lwu_splunk</dc:creator>
      <dc:date>2019-09-10T22:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: SA-Eventgen and Splunk SPL Examples - Help Generating Data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SA-Eventgen-and-Splunk-SPL-Examples-Help-Generating-Data/m-p/479399#M134369</link>
      <description>&lt;P&gt;Iwu, I've read the documentation, however, SA-Eventgen isn't working. Do you have a Splunk Enterprise environment configured with SA-Eventgen and SPL Examples working? &lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 12:01:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SA-Eventgen-and-Splunk-SPL-Examples-Help-Generating-Data/m-p/479399#M134369</guid>
      <dc:creator>dillardo_2</dc:creator>
      <dc:date>2019-09-11T12:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: SA-Eventgen and Splunk SPL Examples - Help Generating Data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SA-Eventgen-and-Splunk-SPL-Examples-Help-Generating-Data/m-p/479400#M134370</link>
      <description>&lt;P&gt;Try to extract this file under &lt;CODE&gt;$SPLUNK_HOME/etc/apps&lt;/CODE&gt; folder and enable Eventgen modular input to check if data is generating into splunk: &lt;A href="https://gofile.io/?c=C9X63g"&gt;https://gofile.io/?c=C9X63g&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 01:42:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SA-Eventgen-and-Splunk-SPL-Examples-Help-Generating-Data/m-p/479400#M134370</guid>
      <dc:creator>lwu_splunk</dc:creator>
      <dc:date>2019-09-12T01:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: SA-Eventgen and Splunk SPL Examples - Help Generating Data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/SA-Eventgen-and-Splunk-SPL-Examples-Help-Generating-Data/m-p/479401#M134371</link>
      <description>&lt;P&gt;We are no longer publishing eventgen configs with TAs :(. &lt;BR /&gt;
I'm going to try to reach out to you directly.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 16:15:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/SA-Eventgen-and-Splunk-SPL-Examples-Help-Generating-Data/m-p/479401#M134371</guid>
      <dc:creator>lnetto_splunk</dc:creator>
      <dc:date>2020-03-19T16:15:04Z</dc:date>
    </item>
  </channel>
</rss>

