Training + Certification Discussions

Splunk Eventgen

hnguyen41
Engager

I am new to Splunk. I tried to install SA_Eventgen app. When I went to apps directory (/opt/slunk/etc/apps/SA_Eventgen/local), I get permission denied. Can anyone explained it to me please? I could not find the tutorial video for the eventgen app either, if someone know where can I find a tutorial session?

Thank a lot.

ehollima
Path Finder

Appendix B: Eventgen troubleshooting tips:
http://dev.splunk.com/view/dev-guide/SP-CAAAE3E

0 Karma

hnguyen41
Engager

Do you know why I am not allowed to access the local directory for that app?

0 Karma

ehollima
Path Finder

Here are 2 resources to help you:
I use this one, it is straight forward and works with any TA that has eventgen files:
https://github.com/coccyx/eventgen

Recent find I am investigating:
https://github.com/splunk/eventgen

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...