ReadyThreatGo creates simulated events in Splunk that go into an index and the various datamodels in order to test detection coverage. The events are stored in lookups which already include sample events but can be modified or added to depending on what you want to simulate.