Splunk Enterprise

Eventgen - Share a token replacement value across multiple events of the same sample file

kirtigupta
Observer

Hi,

I am using Splunk 9.4.1 and eventgen 8.1.2. In my sample file to generate events I have multiple events in the same sample file. 

Sample file:

key1={val_1};key2={val2} - Event 1

key1={val_1;key2={val2} - Event 2 in next line

Now I need to generate a replacement value, any random GID and replace both val_1 in both the events with the same GID. That is I need to share this. But currently splunk eventgen is not sharing the value but a for each event within the file a new value is being generated.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...