splunk / eventgen

Splunk Event Generator: Eventgen
Apache License 2.0
376 stars 180 forks source link

change log dir to $SPLUNK_HOME/var/log/splunk in modinput #384

Closed GordonWang closed 4 years ago

GordonWang commented 4 years ago

flush all the logs to splunk log dir when using Sa-eventgen, then, we can use index=_internal eventgen to search the modinput log of eventgen.