Hello,
I'm trying to set up the SA-eventgen app and doing the simple tutorial with sample files but got this fatal error
"function \"seqfile\" not defined" and this intermediate "error parsing token newline: {{$templateData}}" :
And I don't know why...
Here is my eventgen located in misp42splunk app
sudo cat ./etc/apps/misp42splunk/default/eventgen.conf
[film.json] index = main count = 100 mode = sample end = 1 autotimestamp = true sourcetype = json source = /opt/splunk/sources/film.json token.0.token = "FILM_ID":(\d+) token.0.replacementType = integerid token.0.replacement = 100 token.1.token = "REGION_ID":(\d+) token.1.replacementType = seqfile token.1.replacement = /opt/splunk/etc/apps/sample_conf/samples/count10.txt
Im facing a similar issue while following the tutorial mentioned by Splunk.
thanks for telling me i know that someone else got similar issue with json error parsing as well
Hey,
I kept exploring the documentation and discovered that token replacement type no longer has a seqfile value defined. So if you replace 'seqfile' with 'file' in your conf file, it should start working.