splunk / eventgen

Splunk Event Generator: Eventgen
Apache License 2.0
376 stars 180 forks source link

[BUG] Unable to use existing eventgen.conf from 5.x with 6.x or 7.x #398

Open ryanfaircloth opened 4 years ago

ryanfaircloth commented 4 years ago

Describe the bug Regex syntax of stanzas are no longer supported

To Reproduce See Splunk-TA-juniper

Expected behavior stanzas should be applied based on regex match to sample name as with EG5.x

Actual behavior No events are generated

Screenshots If applicable, add screenshots to help explain your problem.

Sample files and eventgen.conf file Please attach your sample files and eventgen conf file

Do you run eventgen with SA-eventgen? Yes/No(No means you run eventgen with pip module mode)

If you are using SA-Eventgen with Splunk (please complete the following information):

If you are using eventgen with pip module mode (please complete the following information):

Additional context Add any other context about the problem here.

satellite-no commented 2 years ago

Is this planned to be fixed soon? Very annoying bug!