Splunk Search
Highlighted

SA-Eventgen and Splunk SPL Examples - Help Generating Data

Path Finder

Hello community, I've installed SA-Eventgen and SPL Examples as directed in the following .conf talk:

https://conf.splunk.com/files/2017/recordings/creating-your-own-splunk-learning-environment.mp4

However, this doesn't work. I've taken a look at the documentation, created a folder named "local" under the SPLExamples directory and moved the eventgen.config from the apps\splexamples\default folder to the apps\spl_exampels\local folder. I restarted Splunk and still getting no events. What am I missing? Luke Netto's talk referenced above makes it seem so trivial?

I'm working with a brand new install of Splunk on a Windows 10 system. The only apps I've installed as of this post are SA-Eventgen and SPL Examples.

Splunk Enterprise Version: 7.3.1
SA-Eventgen Version: 6.5.1
Splunk SPL Examples Version: 1.0.0

Appreciate any help with this!

Here are some of the errors I'm seeing in the internal index:

alt text

From Splunkd.log:

09-11-2019 12:21:10.206 -0500 ERROR ExecProcessor - message from "python "C:\Program Files\Splunk\etc\apps\SA-Eventgen\bin\modinputeventgen.py"" 2019-09-11 12:21:10 eventgen WARNING MainProcess {'positionalargs': (0,), 'event': 'Generator Queue Full. Reput the backfill generator task later. %d backfill generators are dispatched.'}

0 Karma
Highlighted

Re: SA-Eventgen and Splunk SPL Examples - Help Generating Data

Splunk Employee
Splunk Employee

Here is the latest documentation for Eventgen: http://splunk.github.io/eventgen/

0 Karma
Highlighted

Re: SA-Eventgen and Splunk SPL Examples - Help Generating Data

Path Finder

Iwu, I've read the documentation, however, SA-Eventgen isn't working. Do you have a Splunk Enterprise environment configured with SA-Eventgen and SPL Examples working?

0 Karma
Highlighted

Re: SA-Eventgen and Splunk SPL Examples - Help Generating Data

Splunk Employee
Splunk Employee

Try to extract this file under $SPLUNK_HOME/etc/apps folder and enable Eventgen modular input to check if data is generating into splunk: https://gofile.io/?c=C9X63g

0 Karma
Highlighted

Re: SA-Eventgen and Splunk SPL Examples - Help Generating Data

Splunk Employee
Splunk Employee

We are no longer publishing eventgen configs with TAs :(.
I'm going to try to reach out to you directly.

0 Karma