All Apps and Add-ons

Is there a way to create 6 months of historical data in Splunk for application testing?

simpkins1958
Contributor

Is there a way to create 6 months of data in Splunk so we can test an application we are creating? I've looked at Eventgen, but don't see a way to create data starting 6 months in the past.

0 Karma
1 Solution

simpkins1958
Contributor

Looks like eventgen can do this:

Added backfill support to allow the event generator to start up and immediately generate a user configurable amount of time's worth of events in the past. Also supports defining a search to only backfill where there is a gap.

View solution in original post

csharp_splunk
Splunk Employee
Splunk Employee

Yes, that's supported, although we didn't support generating data for a specified time range because there was no way to end generation. That's been added in the latest dev build, and is documented in the spec file: https://github.com/splunk/eventgen/blob/dev/README/eventgen.conf.spec#L271. If you want to grab the latest build, grab the dev branch: https://github.com/splunk/eventgen/tree/dev.

simpkins1958
Contributor

When using eventgen is the indexed data counted towards the daily maximum?

0 Karma

simpkins1958
Contributor

Looks like eventgen can do this:

Added backfill support to allow the event generator to start up and immediately generate a user configurable amount of time's worth of events in the past. Also supports defining a search to only backfill where there is a gap.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...