Closed lsnow11 closed 4 years ago
The tutorial seems out of date because the conf file is using the "timestamp" token replacement type instead of "replaytimestamp". Can you change this setting for each token replacement and confirm you are getting the desired behavior?
sorry for the delay in testing this. no change in output after changing "timestamp" to "replaytimestamp":
$ python -m splunk_eventgen generate SA-Eventgen/lib/splunk_eventgen/README/eventgen.conf.tutorial1 11-20-2019 08:59:15.000000 INFO Metrics - group=mpool, max_used_interval=11259, max_used=95646, avg_rsv=251, capacity=268435456, used=0 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=fschangemanager, processor=fschangemanager, cpu_seconds=0.000000, executes=1, cumulative_hits=506 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=fschangemanager, processor=sendindex, cpu_seconds=0.000000, executes=1, cumulative_hits=506 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=indexerpipe, processor=http-output-generic-processor, cpu_seconds=0.000000, executes=78, cumulative_hits=46081 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=indexerpipe, processor=indexin, cpu_seconds=0.000000, executes=78, cumulative_hits=46081 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=indexerpipe, processor=index_thruput, cpu_seconds=0.000000, executes=76, cumulative_hits=44392 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=indexerpipe, processor=indexandforward, cpu_seconds=0.000000, executes=78, cumulative_hits=46081 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=indexerpipe, processor=indexer, cpu_seconds=0.000000, executes=78, cumulative_hits=46081 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=indexerpipe, processor=signing, cpu_seconds=0.000000, executes=78, cumulative_hits=46081 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=indexerpipe, processor=syslog-output-generic-processor, cpu_seconds=0.000000, executes=78, cumulative_hits=46081 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=indexerpipe, processor=tcp-output-generic-processor, cpu_seconds=0.000000, executes=78, cumulative_hits=46081 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=merging, processor=aggregator, cpu_seconds=0.000000, executes=48, cumulative_hits=31355 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=merging, processor=readerin, cpu_seconds=0.000000, executes=48, cumulative_hits=31355 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=merging, processor=sendout, cpu_seconds=0.000000, executes=47, cumulative_hits=30025 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=parsing, processor=header, cpu_seconds=0.000000, executes=48, cumulative_hits=31355 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=parsing, processor=linebreaker, cpu_seconds=0.000000, executes=49, cumulative_hits=32921 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=parsing, processor=readerin, cpu_seconds=0.000000, executes=4, cumulative_hits=4585 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=parsing, processor=sendout, cpu_seconds=0.000000, executes=48, cumulative_hits=31355 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=parsing, processor=utf8, cpu_seconds=0.000000, executes=49, cumulative_hits=32921 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=typing, processor=annotator, cpu_seconds=0.000000, executes=47, cumulative_hits=30025 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=typing, processor=previewout, cpu_seconds=0.000000, executes=47, cumulative_hits=30025 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=typing, processor=readerin, cpu_seconds=0.000000, executes=47, cumulative_hits=30025 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=typing, processor=regexreplacement, cpu_seconds=0.000000, executes=47, cumulative_hits=30025 11-20-2019 08:59:15.000000 INFO Metrics - group=pipeline, name=typing, processor=sendout, cpu_seconds=0.000000, executes=47, cumulative_hits=30025 11-20-2019 08:59:15.000000 INFO Metrics - group=searchscheduler, dispatched=0, skipped=0, total_lag=0, max_ready=0, max_pending=0, max_lag=0, max_running=0, actions_triggered=0, completed=0, total_runtime=0.000, max_runtime=0.000
Hmm, I'm not seeing that behavior anymore. I would let it run for a minute or 2 so that it dumps more events on a new interval. You should see new events continue to generate with the current timestamp. It's hard to tell what's going on based on your output, since it's entirely possible that 20-25 events could have the same timestamp. If you still have issues, please output to a file and attach here.
Was this issue fixed? I saw a pr is already merged: https://github.com/splunk/eventgen/pull/351
The issue should be fixed, but I was awaiting follow-up. @lsnow11 please re-open and attach your output file if you still have issues.
Description Replay mode does not seem to be working as expected. I am having problems with my own sample, and I'm also seeing issues with the data generated by eventgen.conf.tutorial1. The issue with the tutorial described below may just mean that the tutorial needs updating, but since I'm having issues of my own with replay, it would be nice to have something working to refer to.
To Reproduce Steps to reproduce the behavior:
python -m splunk_eventgen generate SA-Eventgen/lib/splunk_eventgen/README/eventgen.conf.tutorial1
Expected behavior Timestamp on event should be changing.
Actual behavior Timestamp is not changing.
Screenshots Command line output shown below With v6.5.0:
With v5.something:
Sample files and eventgen.conf file the samples for the tutorial referenced above are included as part of eventgen
Do you run eventgen with SA-eventgen? yes, but this is faster to see at command line as described above. when i've tried with SA-Eventgen, it's on orca.
If you are using SA-Eventgen with Splunk (please complete the following information):
If you are using eventgen with pip module mode (please complete the following information):