The SA-Eventgen App has disappeared in the 3.0.0 version of the Splunk App for Enterprise Security. Is there a new way to generate sample data or are we supposed to use the eventgen from github (https://github.com/splunk/eventgen) if there is a need to generate sample data?
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Yes, just use the one from GitHub. The samples and .conf files are still in all the TAs, so you just need to add in the package and enable it.
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Yes, just use the one from GitHub. The samples and .conf files are still in all the TAs, so you just need to add in the package and enable it.
Thanks Jack
