I agree, the docs hosted at http://splunk.github.io/eventgen/ are incredibly confusing for first-timers.
They don't make clear a simple fact, for example, that you need a combination of event templates and files containing rotating values (users, hosts, etc) in order to get the tool running. You have to find the templates based on real log strings or build your own. local/eventgen.conf stores this combined config. Everything else is secondary.
rav3n's Splunk EventGen — Quick Tutorial on Medium helped me to get started and to wrap my head around how eventgen works. Check it out here: https://medium.com/@rav3n/splunk-eventgen-quick-tutorial-593f526bafc1.
... View more