Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

Thank You

Downloading Eventgen
SHA256 checksum (eventgen_621.tgz) c72fa72204f937c4621d6451c9ce71b79a4b2968493f733da7e9a79f24f57ff3
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate


Splunk Built
Eventgen allows an app developer to describe, through configuration or code, events to generate. This allows an app developer to get events into Splunk to test their applications.

Eventgen is used internally at Splunk for developing numerous applications and demos. It provides a somewhat ridiculous amount of configurability to allow users to simulate real data.

Developers provide an eventgen.conf file and a set of sample files. The eventgen.conf describes configuration settings for each sample and set of token replacements, which match a regular expression and provide a number of methods of substituting data. Samples can run in sample mode, which takes a number of events from the file and sends them to Splunk after substitution, replay mode which will sequentially run through the file and emit events as they occurred in time order by waiting the amount of time between events before emitting the next event, or using custom generators where the developer can write python code to generate events.

The Splunk Event Generator

The Splunk Event Generator is a utility which allows its user to easily build real-time event generators.
The current maintainers of this project are Brian Bingham (bbingham@splunk.com) and Tony Lee (tonyl@splunk.com).

The goals of this project are ambitious but simple:

  • Eliminate the need for hand coded event generators in Splunk apps.
  • Allow for portability of event generators between applications, and allow templates to be quickly adapted between use cases.
  • Allow every type of event or transaction to be modeled inside Eventgen.

To get you started, please setup a documentation


Documentation is packaged through Gitbook.
It is free to use and easy to install Installation Guide.
Once you have Gitbook installed, run Gitbook to serve documentation directory.


Please note CONTRIBUTING.md. You can also find past and current contributors in the document.


The Splunk Event Generator is licensed under the Apache License 2.0. Details can be found in the LICENSE file.


This software is released as-is. Splunk provides no warranty and no support on this software.
If you have any issues with the software, please feel free to reach out to the current maintainers and we would be happy to help you.

Release Notes

Version 6.2.1
June 1, 2018

- Fixing SA-Eventgen Dashboard and log searching
- Improving internal logging and fixing splunkd logging issue
- Fixing timestamping in default generator
- Fixing custom plugin integration
- Fixing SA-Eventgen app settings
- Supporting Eventgen 5 backward compatibility with additional features
- Better modinput process management
- Minor Bugfixes with various customer cases


Subscribe Share

Splunk Certification Program

Splunk's App Certification program uses a specific set of criteria to evaluate the level of quality, usability and security your app offers to its users. In addition, we evaluate the documentation and support you offer to your app's users.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2018 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.