Splunk Enterprise Security

How to use Eventgen as a security event generator for Splunk App for Enterprise Security?

dimitryz
Path Finder

Hello all ,

Our company has Splunk ES 3.1.0.
I would like to know how to use SA-Evengen 2.0.3 ( which I downloaded and installed) with Enterprise Security as security event generator.
SA-Evengen seems to work OK,but I don't have any events on ES dashboards.

Shold I use /opt/splunk/etc/apps/TA-sav/default/eventgen.conf ?

I would appreciate any help.

Regards,
Dmitry

1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

1) install ES as instructed
2) download eventgen from https://github.com/splunk/eventgen
3) extract it to etc/apps/SA-Eventgen (yes, it should be named that).
4) review Eventgen in Manage Apps, you may want to make it visible.
5) Restart Splunk

The ES TAs and any new ones I'm involved in have eventgen.conf and samples in them that are ready to go.

View solution in original post

matthieu_araman
Communicator

Hello, I've installed ES 3.1 + Eventgen and I've events in security posture coming from eventgen generated logs.
I think I've also installed some other apps with eventgen conf like Splunk for windows architecture.
May you should try to install it alongside ?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi,

1) install ES as instructed
2) download eventgen from https://github.com/splunk/eventgen
3) extract it to etc/apps/SA-Eventgen (yes, it should be named that).
4) review Eventgen in Manage Apps, you may want to make it visible.
5) Restart Splunk

The ES TAs and any new ones I'm involved in have eventgen.conf and samples in them that are ready to go.

jcoates_splunk
Splunk Employee
Splunk Employee

you need to enable some correlation searches to get notable events

dimitryz
Path Finder

Hi jcoates_splunk,

Thank you for your help.
Most of the events are shown,but I do have a question.
I still don't see any events on Security Posture and Event Investigators.
Does it mean that it need some more work to do ?

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...