I had this issue/error message but expanding $SPLUNK_HOME to the full path in eventgen.conf token.2.replacement = /opt/splunk/etc/apps/SA-Eventgen/samples/partner.sample:1 and replacing all the windows carriage returns ^M with unix ones in my sample files and then restarting splunk fixed my issues.
... View more