Open breakfixrepeat opened 2 years ago
Looks like the first part of the bug resides in https://github.com/splunk/eventgen/blob/52542a6565ab75d7f1ad7debbdf75cfa9b79d226/splunk_eventgen/lib/plugins/generator/replay.py#L176
The first events time difference should be set to the next event, i.e. line_list[index + 1]["timediff"]
to resolve the issue with the first two events being replayed at the same time.
After that the time diff needs to be updated to the next event in the list.
I will submit a pull request when I get a chance.
Describe the bug Replay mode appears to have a bug whereby the first two events are replayed at the same time, and for each event thereafter the time offset applied from one event to the next is off by 1 event.
To Reproduce Steps to reproduce the behavior:
Expected behavior Each log should be replayed 5 seconds apart, except the 5th log entry should be replayed 5 minutes after the previous
Actual behavior The first two logs are replayed with the same time, all subsequent logs are offset by the previous logs offset.
Sample files and eventgen.conf file eventgen.conf
test.log
Do you run eventgen with SA-eventgen? No
If you are using eventgen with pip module mode (please complete the following information):