All Apps and Add-ons

Is there a way to create 6 months of historical data in Splunk for application testing?

simpkins1958
Contributor

Is there a way to create 6 months of data in Splunk so we can test an application we are creating? I've looked at Eventgen, but don't see a way to create data starting 6 months in the past.

0 Karma
1 Solution

simpkins1958
Contributor

Looks like eventgen can do this:

Added backfill support to allow the event generator to start up and immediately generate a user configurable amount of time's worth of events in the past. Also supports defining a search to only backfill where there is a gap.

View solution in original post

csharp_splunk
Splunk Employee
Splunk Employee

Yes, that's supported, although we didn't support generating data for a specified time range because there was no way to end generation. That's been added in the latest dev build, and is documented in the spec file: https://github.com/splunk/eventgen/blob/dev/README/eventgen.conf.spec#L271. If you want to grab the latest build, grab the dev branch: https://github.com/splunk/eventgen/tree/dev.

simpkins1958
Contributor

When using eventgen is the indexed data counted towards the daily maximum?

0 Karma

simpkins1958
Contributor

Looks like eventgen can do this:

Added backfill support to allow the event generator to start up and immediately generate a user configurable amount of time's worth of events in the past. Also supports defining a search to only backfill where there is a gap.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...