-
Notifications
You must be signed in to change notification settings - Fork 180
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[BUG] Issues detecting custom plugins #279
Comments
@lsnow11 you should place your custom generator plugins under |
Even after moving my plugins to the Eventgen app (v6.5.1) it doesn't look like my plugins are being used, though I do see them being loaded.
|
@lsnow11 I tried with the
I can generate all the data after I copy these four The other thing is custom plugins. I can not get any information about the custom plugins you have written, so I can not give any advice here. |
The only app I'm concernd with is itsidemo_datagen. The rest use samples rather than plugins. To the best of my knowledge, samples work fine as you have stated. |
the generator plugin is working fine, that's not the problem. the problem is that the output plugin is supposed to aggregate some of the data from the generator and generate some new data and this is not happening. |
@lsnow11 I tried with your custom output plugin Here are the changes I made:
You can use file compare tool to see the changes. Hope it work for you. |
I took your appsummarize.py and copied it into the repo, but I'm still not seeing it get used by eventgen: |
So if you are using the Eventgen App aka SA-Eventgen, you can not change the An alternative way is put your output logic in |
Feel free to reopen it if you got further issues. |
I have created several custom plugins with a prior version of eventgen that I am trying to port.
I have put my plugins in the lib folder structure that sa-eventgen uses (subdirs for each type of plugin). When running v6.3.0, my generator plugins are found but not raters or output. I added logging to list out all the discovered plugins and I see all my generator plugins but none of the others. Moving or copying them to bin does not change the behavior. For the output plugin, it seems to just be ignoring the outputMode setting entirely - I don't receive any errors, but I'm definitely not hitting the plugin.
To Reproduce
Pull the demo-itsi-2019 repo from Splunk internal git, eventgen6 branch.
On a fresh Splunk install, run
/opt/splunk/bin/splunk cmd python configureITSIdemo
to install the demo. This will take a while.Enable the Eventgen modular input.
Search
index=itsidemo
for at least last 60 minutes. You will see five sourcetypes. There should be more that are created by the output plugin.Expected: at least eight sourcetypes
Actual: five sourcetypes
Screenshots

list of loaded plugins
Sample files and eventgen.conf file
Please grab from Splunk internal git as noted above
Do you run eventgen with SA-eventgen?
Yes
If you are using SA-Eventgen with Splunk (please complete the following information):
Additional context
Saw the same issue with rater, but I was using an older version and have not tested again with 6.3.0. Not being able to find the rater caused eventgen to throw errors that the plugin could not be found. I do not get errors for the missing output plugin, it is just not used.
The text was updated successfully, but these errors were encountered: