Splunk Enterprise Security

SA-Eventgen is not generate event

leeyounsoo
Path Finder

Hi, Splunk.
I have a question about SA-Eventgen.

I installed the Splunk Enterprise Security app and the SA-Eventgen app, and I want to create dashboards with randomly generated event data. (Data from TA apps that are installed automatically during ES installation)

Once installed, some data is generated, but once every two days, once every three days, no data is generated for an instant.

I erased the SA-Eventgen app and tried reinstalling it, but the results were the same.

What should I do?

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@leeyounsoo

Can you please check Splunk App Installation / First Run section from http://splunk.github.io/eventgen/SETUP.html#install . I think you have to enable SA Eventgen Data Input.

If SA-Eventgen App is correctly installed, there is no additional configuration required. SA-Eventgen app will automatically identify with any apps with eventgen.conf.

To start generating data, simply enable the SA-Eventgen modinput by going to Settings > Data Inputs > SA-Eventgen and by clicking “enable” on the default modular input stanza.
0 Karma

hijacob
Communicator

Do you know Gogen? On GitHub you can get more information https://github.com/coccyx/gogen

Best wishes,
Jacob

0 Karma

leeyounsoo
Path Finder

It was installed and activated by clicking the enable button.
But it is not being collected today.

Splunk just collecting this data

==== sourcetype =======
Perfmon:CPU
PerfmonMk:CPU
PerfmonMk:LogicalDisk
.......
modular_alerts:notable
modular_alerts:risk
nessus
protocol
ps

......

but, i need this data
==== sourcetype =======
bluecoat:proxysg:access:file
bluecoat:proxysg:access:syslog
......
sophos:computerdata
sophos:devicecontrol
sophos:firewall

......

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Once installed, some data is generated, but once every two days, once every three days, no data is generated for an instant
Please update us some more details -
How Eventgen app was configured? did you try some sample templates from the Eventgen app?

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...