All Apps and Add-ons

Splunk App for Windows Infrastructure: Does anyone know where could I get a eventgen.conf for the app as starting point?

claudiocruz
Engager

I'm trying to generate data using eventgen for the APP for Windows Infrastructure but I can't find the eventgen.conf within the app directory.
Does anyone know where could I get a eventgen.conf for the app as a starting point?
Is that even provided with this app?

Any assistance is appreciated.

0 Karma
1 Solution

adonio
Ultra Champion

do you have the eventgen app on your splunk instance?
install the splunk TA for windows, navigate to the default directory, youll find eventgen.conf file there.
you can find sample data in teh samples directory of the same app.
enable the eventgen and windows data will start populating your App for Windows Infrastructure dashboards.

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

do you have the eventgen app on your splunk instance?
install the splunk TA for windows, navigate to the default directory, youll find eventgen.conf file there.
you can find sample data in teh samples directory of the same app.
enable the eventgen and windows data will start populating your App for Windows Infrastructure dashboards.

hope it helps

0 Karma

sapanda
Path Finder

hello @adonio ,

I have setup the event gen and the data for the windows app is coming to the index. I want to configure the same for different hosts though, i tried adding the host.replacement token but it does not seem to work. any suggestions?

thanks,
Sapan

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...