All Apps and Add-ons

EVENTGEN: Ingests events after installation automatically

kumaranv
Path Finder
Once installed the SA-Eventgen app and enabled the SA-Eventgen data input, it started ingest events for following sourcetype. but i don't see any configuration in eventgen.conf file. How is this happening.
Thanks
bro:http:json
bro:weird:json
bro_conn
bro_dhcp
bro_ftp
bro_notice
bro_smtp
bro_ssh
bro_tunnel
cisco:sourcefire
eStreamer
mcafee:ids
oracle:alert:text
oracle:audit:text
oracle:connections
oracle:database
oracle:database:size
oracle:dbFileIoPerf
oracle:incident
oracle:instance
oracle:libraryCachePerf
oracle:listener:text
oracle:osPerf
oracle:pool:connections
oracle:query
oracle:session
oracle:sga
oracle:sysPerf
oracle:table
oracle:tablespace
oracle:tablespaceMetrics
oracle:trace
oracle:user
snort
sophos:appcontrol
sophos:computerdata
sophos:devicecontrol
sophos:firewall
Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The docs at http://splunk.github.io/eventgen/SETUP.html#install say no configuration is needed.

If SA-Eventgen App is correctly installed, there is no additional configuration required. SA-Eventgen app will automatically identify with any apps with eventgen.conf.

The apps that define the listed sourcetypes probably contain their own eventgen.conf files, which the TA found and used to generate events.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The docs at http://splunk.github.io/eventgen/SETUP.html#install say no configuration is needed.

If SA-Eventgen App is correctly installed, there is no additional configuration required. SA-Eventgen app will automatically identify with any apps with eventgen.conf.

The apps that define the listed sourcetypes probably contain their own eventgen.conf files, which the TA found and used to generate events.

---
If this reply helps you, Karma would be appreciated.
0 Karma

kumaranv
Path Finder

Perfect.
as you mentioned, eventgen.conf files are there in other apps also which eventgen app is processing.
Thanks

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...