Splunk Enterprise

Eventgen generating metric data- how to resolve error?

robertlynch2020
Influencer

Hi

I am using Eventgen to create metric data. I have it working for events.

I want to get up a very basic example timestamp and metric with the basic value, below, but I am getting an error message.

 

 

 

The metric event is not properly structured, source=bcgames, sourcetype=addons, host=buttercup, index=bcg_eventgen_metrics. Metric event data without a metric name and properly formated numerical values are invalid and cannot be indexed. Ensure the input metric data is not malformed, have one or more keys of the form "metric_name:<metric>" (e.g..."metric_name:cpu.idle") with corresponding floating point values.

 

 

 

 

 

 

 

[sample.lab2data]
interval = 2m
earliest = -2m
latest = now
backfill = -1d

outputMode = metric_httpevent

index = bcg_eventgen_metrics
host = buttercup
source = bcgames
sourcetype = sales:addons

token.0.token = !timestamp!
token.0.replacementType = timestamp
token.0.replacement = %H:%M:%S %b-%d-%Y

token.1.token = !1!
token.1.replacementType = random
token.1.replacement = integer[1:3]

 

 

 

sample.lab2.data

 

 

 

timestamp=!timestamp! metric_name:cpu.idle=!1!

 

 

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...