All Apps and Add-ons

EVENTGEN: Ingests events after installation automatically

kumaranv
Path Finder
Once installed the SA-Eventgen app and enabled the SA-Eventgen data input, it started ingest events for following sourcetype. but i don't see any configuration in eventgen.conf file. How is this happening.
Thanks
bro:http:json
bro:weird:json
bro_conn
bro_dhcp
bro_ftp
bro_notice
bro_smtp
bro_ssh
bro_tunnel
cisco:sourcefire
eStreamer
mcafee:ids
oracle:alert:text
oracle:audit:text
oracle:connections
oracle:database
oracle:database:size
oracle:dbFileIoPerf
oracle:incident
oracle:instance
oracle:libraryCachePerf
oracle:listener:text
oracle:osPerf
oracle:pool:connections
oracle:query
oracle:session
oracle:sga
oracle:sysPerf
oracle:table
oracle:tablespace
oracle:tablespaceMetrics
oracle:trace
oracle:user
snort
sophos:appcontrol
sophos:computerdata
sophos:devicecontrol
sophos:firewall
Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The docs at http://splunk.github.io/eventgen/SETUP.html#install say no configuration is needed.

If SA-Eventgen App is correctly installed, there is no additional configuration required. SA-Eventgen app will automatically identify with any apps with eventgen.conf.

The apps that define the listed sourcetypes probably contain their own eventgen.conf files, which the TA found and used to generate events.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The docs at http://splunk.github.io/eventgen/SETUP.html#install say no configuration is needed.

If SA-Eventgen App is correctly installed, there is no additional configuration required. SA-Eventgen app will automatically identify with any apps with eventgen.conf.

The apps that define the listed sourcetypes probably contain their own eventgen.conf files, which the TA found and used to generate events.

---
If this reply helps you, Karma would be appreciated.
0 Karma

kumaranv
Path Finder

Perfect.
as you mentioned, eventgen.conf files are there in other apps also which eventgen app is processing.
Thanks

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...