You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
index,host,source,sourcetype,_raw
eventgenTest,splunk,/var/log/radius.log,radius,May 27 18:28:11:000 aaa2 radiusd[12676]:[ID 959576 local1.info] INFO RADOP(13) acct start for 5559031692@splunktel.com 10.94.63.34 from 130.253.37.97 recorded OK.
eventgenTest,splunk,/var/log/httpd/access_log,access_custom,"2012-05-27 18:28:11:112 10.2.1.35 POST /playhistory/uploadhistory - 80 - 10.94.63.34 ""Mozilla/5.0 (iPhone; CPU iPhone OS 5_0_1 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9A405 Safari/7534.48.3"" 503 0 0 468 1488"
eventgenTest,splunk,/var/log/httpd/access_log,access_custom,"2012-05-27 18:28:11:125 10.2.1.35 GET /sync/addtolibrary/01011207201000005652000000000047 - 80 - 10.94.63.34 ""Mozilla/5.0 (iPhone; CPU iPhone OS 5_0_1 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9A405 Safari/7534.48.3"" 200 0 0 468 1488"
eventgenTest,splunk,/var/log/httpd/access_log,access_custom,"2012-05-27 18:28:11:137 10.2.1.35 GET /sync/addtolibrary/01011207201000005652000000000047 - 80 - 10.94.63.34 ""Mozilla/5.0 (iPhone; CPU iPhone OS 5_0_1 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9A405 Safari/7534.48.3"" 503 0 0 468 1488"
eventgenTest,splunk,/var/log/radius.log,radius,May 27 18:28:11:199 aaa2 radiusd[12676]:[ID 959576 local1.info] INFO RADOP(13) acct stop for 5559031692@splunktel.com 10.94.63.34 from 130.253.37.97 recorde
Do you run eventgen with SA-eventgen?
No
If you are using eventgen with pip module mode (please complete the following information):
python version: 3.6
OS: MacOS
Virtual Env is used: Yes
Eventgen Version: 7.0.0
Additional context
Relevant token.X.replacement docs on passing a list of strptime expressions (seems supported): "For ["list","of","strptime"], only used with replaytimestamp, a JSON formatted list of strptime formats to try."
The text was updated successfully, but these errors were encountered:
On second thought, I don't think this is the right/accepted approach, nor required by anyone right now--Closing
This conf actually came from our own tutorial4. It's not being used anywhere, but there is also a small mention of this feature in our docs. We should investigate the issue and add tests/docs for this feature if we plan on supporting it.
Describe the bug
Events are not generated when I use multiple strptime expressions for a single token.
To Reproduce
Generate with included files
Expected behavior
Both strptime expressions are evaluated/written with the correct replaytimestamp
Actual behavior
Nothing is generated
Sample files and eventgen.conf file
eventgen.conf:
sample:
Do you run eventgen with SA-eventgen?
No
If you are using eventgen with pip module mode (please complete the following information):
Additional context
Relevant token.X.replacement docs on passing a list of strptime expressions (seems supported): "For ["list","of","strptime"], only used with replaytimestamp, a JSON formatted list of strptime formats to try."
The text was updated successfully, but these errors were encountered: