Using Eventgen in Splunk Lab

What Is Eventgen?

Because a Docker container is quicker than spinning up a VM.

Why Use Eventgen?

How Eventgen Is Used in Splunk Lab

How To Spin Up Splunk Lab with Eventgen?

SPLUNK_EVENTGEN=1 bash <(curl -Ls https://bit.ly/splunklab)
ASCII Art. Just like logging into your favorite BBS.
“Now with CIM Compliance!”
Still a better love story than Twilight.

How To Configure Eventgen?

docker run -d -p 8000:8000 \
-v $(pwd)/splunk-lab-app:/opt/splunk/etc/apps/splunk-lab \
-e SPLUNK_PASSWORD=password1 \
-e SPLUNK_EVENTGEN=1 \
--name splunk-lab \
dmuth1/splunk-lab
docker exec -it splunk-lab bash

Credits

Engineer. AWS, CyberSec, DMARC, Docker, Splunk, White Mage. Staffs way too many furry cons. he/him. 28% Cheetah.