TA lacking eventgen
randolpht opened this issue · 3 comments
randolpht commented
Are you guys not including eventgen in this revision of the TA?
btorresgil commented
We removed the eventgen because its so big. At 30 MB, it seemed silly to redistribute that across every SearchHead, Indexer, and Heavy Forwarder. The eventgen comes packaged with the docker version of the app: https://hub.docker.com/r/btorresgil/splunk-panw-demo
Do you want it added back into the TA? What's the use case?
randolpht commented
Nope. I just have done some stuff for my internal lab with the eventgen. I will grab it from your docker version.
Thanks!
btorresgil commented
Sounds good, thanks! Closing, but commenting is still open if there are other opinions to share on this.