All Apps and Add-ons

EVENTGEN: Ingests events after installation automatically

kumaranv
Path Finder
Once installed the SA-Eventgen app and enabled the SA-Eventgen data input, it started ingest events for following sourcetype. but i don't see any configuration in eventgen.conf file. How is this happening.
Thanks
bro:http:json
bro:weird:json
bro_conn
bro_dhcp
bro_ftp
bro_notice
bro_smtp
bro_ssh
bro_tunnel
cisco:sourcefire
eStreamer
mcafee:ids
oracle:alert:text
oracle:audit:text
oracle:connections
oracle:database
oracle:database:size
oracle:dbFileIoPerf
oracle:incident
oracle:instance
oracle:libraryCachePerf
oracle:listener:text
oracle:osPerf
oracle:pool:connections
oracle:query
oracle:session
oracle:sga
oracle:sysPerf
oracle:table
oracle:tablespace
oracle:tablespaceMetrics
oracle:trace
oracle:user
snort
sophos:appcontrol
sophos:computerdata
sophos:devicecontrol
sophos:firewall
Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The docs at http://splunk.github.io/eventgen/SETUP.html#install say no configuration is needed.

If SA-Eventgen App is correctly installed, there is no additional configuration required. SA-Eventgen app will automatically identify with any apps with eventgen.conf.

The apps that define the listed sourcetypes probably contain their own eventgen.conf files, which the TA found and used to generate events.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The docs at http://splunk.github.io/eventgen/SETUP.html#install say no configuration is needed.

If SA-Eventgen App is correctly installed, there is no additional configuration required. SA-Eventgen app will automatically identify with any apps with eventgen.conf.

The apps that define the listed sourcetypes probably contain their own eventgen.conf files, which the TA found and used to generate events.

---
If this reply helps you, Karma would be appreciated.
0 Karma

kumaranv
Path Finder

Perfect.
as you mentioned, eventgen.conf files are there in other apps also which eventgen app is processing.
Thanks

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...