I configured an alert when a VPN connection is established from an IP that is located abroad. Now I would like to test if the alert works as expected. What is the best way of doing this? Can I for example copy a raw VPN login event, change the source IP, mark the event as alerttestevent and add it to Splunk to test the alert?
Can this be automated somehow, i.e. when I adjust an alert I want to easily retest that everything still works as expected? I'm thinking about something like unit tests for Splunk alerts.
You can use the Eventgen App to generate events. Take a look this might be your answer.
https://splunkbase.splunk.com/app/1924/
Thank you for the response, I'll take a closer look at the Eventgen App.
Along the lines of your original idea to copy an event and modify it. You could do that and use | collect
command to write it back to your index.
https://docs.splunk.com/Documentation/Splunk/8.0.2/SearchReference/Collect