All Apps and Add-ons

EVENTGEN: Ingests events after installation automatically

kumaranv
Path Finder
Once installed the SA-Eventgen app and enabled the SA-Eventgen data input, it started ingest events for following sourcetype. but i don't see any configuration in eventgen.conf file. How is this happening.
Thanks
bro:http:json
bro:weird:json
bro_conn
bro_dhcp
bro_ftp
bro_notice
bro_smtp
bro_ssh
bro_tunnel
cisco:sourcefire
eStreamer
mcafee:ids
oracle:alert:text
oracle:audit:text
oracle:connections
oracle:database
oracle:database:size
oracle:dbFileIoPerf
oracle:incident
oracle:instance
oracle:libraryCachePerf
oracle:listener:text
oracle:osPerf
oracle:pool:connections
oracle:query
oracle:session
oracle:sga
oracle:sysPerf
oracle:table
oracle:tablespace
oracle:tablespaceMetrics
oracle:trace
oracle:user
snort
sophos:appcontrol
sophos:computerdata
sophos:devicecontrol
sophos:firewall
Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The docs at http://splunk.github.io/eventgen/SETUP.html#install say no configuration is needed.

If SA-Eventgen App is correctly installed, there is no additional configuration required. SA-Eventgen app will automatically identify with any apps with eventgen.conf.

The apps that define the listed sourcetypes probably contain their own eventgen.conf files, which the TA found and used to generate events.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The docs at http://splunk.github.io/eventgen/SETUP.html#install say no configuration is needed.

If SA-Eventgen App is correctly installed, there is no additional configuration required. SA-Eventgen app will automatically identify with any apps with eventgen.conf.

The apps that define the listed sourcetypes probably contain their own eventgen.conf files, which the TA found and used to generate events.

---
If this reply helps you, Karma would be appreciated.
0 Karma

kumaranv
Path Finder

Perfect.
as you mentioned, eventgen.conf files are there in other apps also which eventgen app is processing.
Thanks

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...