Hello all,
I've just installed Splunk 8.0 (the free version) on a relatively uninteresting Windows 10 machine with all current patches. Accepted all defaults except I changed the home directory to "C:\Splunk\" and I selected Python 3.0. Splunk itself works beautifully, as far as I can tell. Without changing anything at all about the configuration, I then got Eventgen 7.0.0 from the splunkbase (https://splunkbase.splunk.com/app/1924/) and installed it per the directions. Upon restarting Splunk, I immediately got this message:
Unable to initialize modular input "modinput_eventgen" defined in the app "SA-Eventgen": Introspecting scheme=modinput_eventgen: script running failed (exited with code 1)..
On the CLI, this:
splunk cmd python modinput_eventgen.py --scheme
produces this:
python: can't open file 'modinput_eventgen.py': [Errno 2] No such file or directory
and when I cd to the app's bin directory and run the same command, I get this:
Traceback (most recent call last):
File "modinput_eventgen.py", line 15, in <module>
from splunk_eventgen import eventgen_core # noqa isort:skip
ImportError: No module named splunk_eventgen
I've tried several variations -- I've installed with Python 2.0, I tried installing Splunk 7.3.2... nothing. I get the same errors every time.
Also, presumably since my problem is more fundamental, there is no "SA-Eventgen" under "Settings > Data Inputs".
I would be very grateful for any and all guidance. Thank you!
--Dan
... View more