PaloAltoNetworks/Splunk_TA_paloalto

TA lacking eventgen

randolpht opened this issue · 3 comments

Are you guys not including eventgen in this revision of the TA?

We removed the eventgen because its so big. At 30 MB, it seemed silly to redistribute that across every SearchHead, Indexer, and Heavy Forwarder. The eventgen comes packaged with the docker version of the app: https://hub.docker.com/r/btorresgil/splunk-panw-demo

Do you want it added back into the TA? What's the use case?

Nope. I just have done some stuff for my internal lab with the eventgen. I will grab it from your docker version.

Thanks!

Sounds good, thanks! Closing, but commenting is still open if there are other opinions to share on this.