1
-
2
1
[pan_traffic.samplelog]
3
2
4
3
outputMode = splunkstream
@@ -650,3 +649,75 @@ disabled = false
650
649
interval = 60
651
650
randomizeEvents = false
652
651
count = 0
652
+
653
+ [pan_xdr_incidents.json]
654
+ outputMode = splunkstream
655
+ disabled = false
656
+ earliest = -60s
657
+ latest = now
658
+ interval = 60
659
+ count = 4
660
+ randomizeCount = 0.2
661
+ randomizeEvents = true
662
+
663
+ sourcetype=pan:xdr_incident
664
+ source = eventgen:pan_xdr_incidents.json
665
+ autotimestamp = 1
666
+
667
+ [pan_iot_device.json]
668
+ index = main
669
+ count = 4
670
+ earliest = -60s
671
+ latest = now
672
+ interval = 6
673
+ mode = sample
674
+ autotimestamp = true
675
+ sourcetype = json
676
+ randomizeCount = 0.2
677
+ randomizeEvents = true
678
+ sourcetype=pan:iot_device
679
+ source = eventgen:pan_iot_device.json
680
+
681
+ token.0.token = "last_activity":(\d+)
682
+ token.0.replacementType = replaytimestamp
683
+ token.0.replacement = %Y-%d-%m %H:%M:%S
684
+
685
+ token.1.token = "first_seen_date":(\d+)
686
+ token.1.replacementType = replaytimestamp
687
+ token.1.replacement = %Y-%d-%m %H:%M:%S
688
+
689
+ [pan_iot_alert.json]
690
+ index = main
691
+ count = 4
692
+ earliest = -60s
693
+ latest = now
694
+ interval = 6
695
+ mode = sample
696
+ autotimestamp = true
697
+ sourcetype = json
698
+ randomizeCount = 0.2
699
+ randomizeEvents = true
700
+ sourcetype=pan:iot_alert
701
+ source = eventgen:pan_iot_alert.json
702
+
703
+ token.0.token = "date":(\d+)
704
+ token.0.replacementType = replaytimestamp
705
+ token.0.replacement = %Y-%d-%m %H:%M:%S
706
+
707
+ [pan_iot_vulnerability.json]
708
+ index = main
709
+ count = 4
710
+ earliest = -60s
711
+ latest = now
712
+ interval = 6
713
+ mode = sample
714
+ autotimestamp = true
715
+ sourcetype = json
716
+ randomizeCount = 0.2
717
+ randomizeEvents = true
718
+ sourcetype=pan:iot_vulnerability
719
+ source = eventgen:pan_iot_vulnerability.json
720
+
721
+ token.0.token = "date":(\d+)
722
+ token.0.replacementType = replaytimestamp
723
+ token.0.replacement = %Y-%d-%m %H:%M:%S
0 commit comments