All Apps and Add-ons

EVENTGEN: Ingests events after installation automatically

kumaranv
Path Finder
Once installed the SA-Eventgen app and enabled the SA-Eventgen data input, it started ingest events for following sourcetype. but i don't see any configuration in eventgen.conf file. How is this happening.
Thanks
bro:http:json
bro:weird:json
bro_conn
bro_dhcp
bro_ftp
bro_notice
bro_smtp
bro_ssh
bro_tunnel
cisco:sourcefire
eStreamer
mcafee:ids
oracle:alert:text
oracle:audit:text
oracle:connections
oracle:database
oracle:database:size
oracle:dbFileIoPerf
oracle:incident
oracle:instance
oracle:libraryCachePerf
oracle:listener:text
oracle:osPerf
oracle:pool:connections
oracle:query
oracle:session
oracle:sga
oracle:sysPerf
oracle:table
oracle:tablespace
oracle:tablespaceMetrics
oracle:trace
oracle:user
snort
sophos:appcontrol
sophos:computerdata
sophos:devicecontrol
sophos:firewall
Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The docs at http://splunk.github.io/eventgen/SETUP.html#install say no configuration is needed.

If SA-Eventgen App is correctly installed, there is no additional configuration required. SA-Eventgen app will automatically identify with any apps with eventgen.conf.

The apps that define the listed sourcetypes probably contain their own eventgen.conf files, which the TA found and used to generate events.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The docs at http://splunk.github.io/eventgen/SETUP.html#install say no configuration is needed.

If SA-Eventgen App is correctly installed, there is no additional configuration required. SA-Eventgen app will automatically identify with any apps with eventgen.conf.

The apps that define the listed sourcetypes probably contain their own eventgen.conf files, which the TA found and used to generate events.

---
If this reply helps you, Karma would be appreciated.
0 Karma

kumaranv
Path Finder

Perfect.
as you mentioned, eventgen.conf files are there in other apps also which eventgen app is processing.
Thanks

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...