All Apps and Add-ons

Eventgen: Getting "ImportError: No module named sharedctypes". Why is this module missing in 6.4 and how do I add it?

rbigeard
Explorer

I'm trying to run the Eventgen app on a Splunk 6.4 installation. It runs fine in thread mode, but fails in "process" mode with the following errors in the logs:

05-25-2016 09:50:51.182 +1000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/eventgen/bin/eventgen_modinput.py" ImportError: No module named sharedctypes
05-25-2016 10:30:08.534 +1000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/eventgen/bin/eventgen_modinput.py"     from multiprocessing.sharedctypes import RawValue

sharedctypes.py is indeed not found in the python deployment coming with 6.4.

What is the cleanest way to add this module?

0 Karma

nzou_splunk
Splunk Employee
Splunk Employee

I met this same error today and I guess you're trying to use event gen to do the scripted input, right? if so, you need to put an eventgen.conf file under you app/default folder. this works for me. You can have a try.

BTW, you can move eventgen/lib/eventgen_defaults to your app/default folder and rename it as eventgen.conf.
Or just move it:
mv ...../lib/eventgen_defaults ....app/default/eventgen.conf

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...