Getting Data In

eventgen and outputMode = s2s not working

New Member


I'm having a real issue trying to get eventgen working.

I'm trying to use the outputMode = s2s but it is bombing out with the below.



2021-07-28 15:06:42 eventgen        ERROR    MainProcess 'utf-8' codec can't decode byte 0xb3 in position 3: invalid start byte
Traceback (most recent call last):
  File "/usr/lib/python3.7/site-packages/splunk_eventgen/", line 304, in _worker_do_work
  File "/usr/lib/python3.7/site-packages/splunk_eventgen/lib/", line 39, in run
  File "/usr/lib/python3.7/site-packages/splunk_eventgen/lib/plugins/output/", line 204, in flush
  File "/usr/lib/python3.7/site-packages/splunk_eventgen/lib/plugins/output/", line 173, in send_event
    e = self._encode_event(index, host, source, sourcetype, _raw, _time)
  File "/usr/lib/python3.7/site-packages/splunk_eventgen/lib/plugins/output/", line 124, in _encode_event
    encoded_raw = self._encode_key_value("_raw", _raw)
  File "/usr/lib/python3.7/site-packages/splunk_eventgen/lib/plugins/output/", line 78, in _encode_key_value
    return "%s%s" % (self._encode_string(key), self._encode_string(value))
  File "/usr/lib/python3.7/site-packages/splunk_eventgen/lib/plugins/output/", line 69, in _encode_string
UnicodeDecodeError: 'utf-8' codec can't decode byte 0xb3 in position 3: invalid start byte




My eventgen.conf file looks like this:



mode = replay
count = -1
timeMultiple = 1
sampletype = raw
# outputMode = tcpout
outputMode = s2s
splunkHost = splunk_search
splunkPort = 9997
source = udp:514
host = boundary-fw1
index = main
sourcetype = cisco:asa
# tcpDestinationHost = splunk_uf1
# tcpDestinationPort = 3333
token.0.token = \w{3} \d{2} \d{2}:\d{2}:\d{2}
token.0.replacementType = replaytimestamp
token.0.replacement = %b %d %H:%M:%S




It works fine with tcpout (the commented out bits above) but not as s2s. 

I'm executing eventgen like this

/usr/bin/python3.7 /usr/bin/splunk_eventgen -v generate /opt/splunk-eventgen/default/eventgen.conf

The reason I'm using s2s is I'd like to generate sample data as if it's coming from many hosts, sources and sourcetypes and I can't do that if I'm using tcpout.

In the above config, splunk_search is a standalone test splunk install. Sending directly to this splunk host via s2s fails.

If I switch back to tcpout, then I'm sending to a Splunk UF with a tcpinput configured which is then sending to splunk_search via tcp/9997

eventgen was installed and configured as per

Any suggestions?

Labels (3)
0 Karma


That error means you have a character in eventgen.conf that can't be decoded. That's usually a copy/paste problem from Windows/web to linux.

Running dos2unix against the file will usually fix that. yum install -y dos2unix (if you don't have it).

[root@:~]$ dos2unix /tmp/eventgen.conf
dos2unix: converting file /tmp/eventgen.conf to Unix format...

An upvote would be appreciated and Accept Solution if it helps!
0 Karma

New Member

Thanks for the suggestion but this hasn't worked.

The error is identical after installing and running the file through dos2unix.

The file was created in vi so I kind of doubted this was the problem.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.