Skip to content
This repository was archived by the owner on Dec 14, 2024. It is now read-only.

Commit 935ab5b

Browse files
authored
chore(demo): Add demo data for IOT and Cortex XDR
PR #185
1 parent 658db2e commit 935ab5b

File tree

5 files changed

+2943
-1
lines changed

5 files changed

+2943
-1
lines changed

demo/conf/eventgen_conf/eventgen.conf

Lines changed: 72 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,3 @@
1-
21
[pan_traffic.samplelog]
32

43
outputMode = splunkstream
@@ -650,3 +649,75 @@ disabled = false
650649
interval = 60
651650
randomizeEvents = false
652651
count = 0
652+
653+
[pan_xdr_incidents.json]
654+
outputMode = splunkstream
655+
disabled = false
656+
earliest = -60s
657+
latest = now
658+
interval = 60
659+
count = 4
660+
randomizeCount = 0.2
661+
randomizeEvents = true
662+
663+
sourcetype=pan:xdr_incident
664+
source = eventgen:pan_xdr_incidents.json
665+
autotimestamp = 1
666+
667+
[pan_iot_device.json]
668+
index = main
669+
count = 4
670+
earliest = -60s
671+
latest = now
672+
interval = 6
673+
mode = sample
674+
autotimestamp = true
675+
sourcetype = json
676+
randomizeCount = 0.2
677+
randomizeEvents = true
678+
sourcetype=pan:iot_device
679+
source = eventgen:pan_iot_device.json
680+
681+
token.0.token = "last_activity":(\d+)
682+
token.0.replacementType = replaytimestamp
683+
token.0.replacement = %Y-%d-%m %H:%M:%S
684+
685+
token.1.token = "first_seen_date":(\d+)
686+
token.1.replacementType = replaytimestamp
687+
token.1.replacement = %Y-%d-%m %H:%M:%S
688+
689+
[pan_iot_alert.json]
690+
index = main
691+
count = 4
692+
earliest = -60s
693+
latest = now
694+
interval = 6
695+
mode = sample
696+
autotimestamp = true
697+
sourcetype = json
698+
randomizeCount = 0.2
699+
randomizeEvents = true
700+
sourcetype=pan:iot_alert
701+
source = eventgen:pan_iot_alert.json
702+
703+
token.0.token = "date":(\d+)
704+
token.0.replacementType = replaytimestamp
705+
token.0.replacement = %Y-%d-%m %H:%M:%S
706+
707+
[pan_iot_vulnerability.json]
708+
index = main
709+
count = 4
710+
earliest = -60s
711+
latest = now
712+
interval = 6
713+
mode = sample
714+
autotimestamp = true
715+
sourcetype = json
716+
randomizeCount = 0.2
717+
randomizeEvents = true
718+
sourcetype=pan:iot_vulnerability
719+
source = eventgen:pan_iot_vulnerability.json
720+
721+
token.0.token = "date":(\d+)
722+
token.0.replacementType = replaytimestamp
723+
token.0.replacement = %Y-%d-%m %H:%M:%S

0 commit comments

Comments
 (0)