<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk for Fortinet FortiOS 5: Is anyone else getting transforms errors &amp;quot;Regex: two named subpatterns have the same name&amp;quot;? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123759#M9631</link>
    <description>&lt;P&gt;Anyone else getting Regex: two named subpatterns have the same name.  Bad regex  for the field extractions in this app? I'm having a day so I want to be sure it isn't just me. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Regex: two named subpatterns have the same name.  Bad regex: (devname\=(?\S+)|clusterid\=(?\S+)) devid\=(?\S+) logid\=(?\S+) (type\=app-ctrl|subtype\=(?\S+)) (subtype\=(?\S+)|type\=app-ctrl) (timestamp=(?\S+) |)pri\=(?\S+) (user=(?\S+) group=(?\S+) profile=(?\S+) srcip\=(?\S+) srcport\=(?\S+) srcintf\=(?\S+) dstip\=(?\S+) dstport\=(?\S+) dstintf\=(?\S+) src_name=(?\S+) dst_name\=(?\S+) proto\=(?\S+) service\=(?\S+) policyid\=(?\S+) serial\=(?\S+) applist\=(?\S+) apptype\=(?\S+) app=(?\S+) action=(?\S+) count=(?\S+) filesize=(?\S+) msg\="(?[^\"]+)" vd=(?\S+) attackid=(?\S+) profiletype=(?\S+) profilegroup=(?\S+) identidx\=(?\S+) hostname\=(?\S+) url\=(?\S+)|vd\="(?[^\"]+)" attackid\=(?\S+) user\="(?[^\"]+)" group="(?[^\"]+)" srcip\=(?\S+) srcport\=(?\S+) srcintf\="(?[^\"]+)" dstip\=(?\S+) dstport\=(?\S+) dstintf\="(?[^\"]+)" src_name\="(?[^\"]+)" dst_name\="(?[^\"]+)" profilegroup\="(?[^\"]+)" profiletype\="(?[^\"]+)" profile\="(?[^\"]+)" proto\=(?\S+) service\=(?\S+) policyid\=(?\S+) identidx\=(?\S+) serial\=(?\S+) applist\="(?[^\"]+)" apptype\="(?[^\"]+)" app\="(?[^\"]+)" action\=(?\S+) count\=(?\S+) hostname\=(?\S+) url\=(?\S+) msg\="(?[^\"]+)")
            Config problem: invalid regex: transforms.conf / [extract_app-ctrlv5] / REGEX
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Over and over again for each extract. I'm running 6.1.4, thanks in advance. &lt;/P&gt;

&lt;P&gt;Bill&lt;/P&gt;</description>
    <pubDate>Tue, 18 Nov 2014 21:06:21 GMT</pubDate>
    <dc:creator>billford</dc:creator>
    <dc:date>2014-11-18T21:06:21Z</dc:date>
    <item>
      <title>Splunk for Fortinet FortiOS 5: Is anyone else getting transforms errors "Regex: two named subpatterns have the same name"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123759#M9631</link>
      <description>&lt;P&gt;Anyone else getting Regex: two named subpatterns have the same name.  Bad regex  for the field extractions in this app? I'm having a day so I want to be sure it isn't just me. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Regex: two named subpatterns have the same name.  Bad regex: (devname\=(?\S+)|clusterid\=(?\S+)) devid\=(?\S+) logid\=(?\S+) (type\=app-ctrl|subtype\=(?\S+)) (subtype\=(?\S+)|type\=app-ctrl) (timestamp=(?\S+) |)pri\=(?\S+) (user=(?\S+) group=(?\S+) profile=(?\S+) srcip\=(?\S+) srcport\=(?\S+) srcintf\=(?\S+) dstip\=(?\S+) dstport\=(?\S+) dstintf\=(?\S+) src_name=(?\S+) dst_name\=(?\S+) proto\=(?\S+) service\=(?\S+) policyid\=(?\S+) serial\=(?\S+) applist\=(?\S+) apptype\=(?\S+) app=(?\S+) action=(?\S+) count=(?\S+) filesize=(?\S+) msg\="(?[^\"]+)" vd=(?\S+) attackid=(?\S+) profiletype=(?\S+) profilegroup=(?\S+) identidx\=(?\S+) hostname\=(?\S+) url\=(?\S+)|vd\="(?[^\"]+)" attackid\=(?\S+) user\="(?[^\"]+)" group="(?[^\"]+)" srcip\=(?\S+) srcport\=(?\S+) srcintf\="(?[^\"]+)" dstip\=(?\S+) dstport\=(?\S+) dstintf\="(?[^\"]+)" src_name\="(?[^\"]+)" dst_name\="(?[^\"]+)" profilegroup\="(?[^\"]+)" profiletype\="(?[^\"]+)" profile\="(?[^\"]+)" proto\=(?\S+) service\=(?\S+) policyid\=(?\S+) identidx\=(?\S+) serial\=(?\S+) applist\="(?[^\"]+)" apptype\="(?[^\"]+)" app\="(?[^\"]+)" action\=(?\S+) count\=(?\S+) hostname\=(?\S+) url\=(?\S+) msg\="(?[^\"]+)")
            Config problem: invalid regex: transforms.conf / [extract_app-ctrlv5] / REGEX
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Over and over again for each extract. I'm running 6.1.4, thanks in advance. &lt;/P&gt;

&lt;P&gt;Bill&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2014 21:06:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123759#M9631</guid>
      <dc:creator>billford</dc:creator>
      <dc:date>2014-11-18T21:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Fortinet FortiOS 5: Is anyone else getting transforms errors "Regex: two named subpatterns have the same name"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123760#M9632</link>
      <description>&lt;P&gt;i have started using it since last few days. no error so far....&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2014 12:16:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123760#M9632</guid>
      <dc:creator>fortinet</dc:creator>
      <dc:date>2014-12-09T12:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Fortinet FortiOS 5: Is anyone else getting transforms errors "Regex: two named subpatterns have the same name"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123761#M9633</link>
      <description>&lt;P&gt;I've installed it on an empty 6.1.4, 6.1.5 and 6.2 splunk (empty as in fresh install) and I get the same errors. I actually reworked it to not get the errors and to be CIM-compliant so my issue is resolved but I'm curious what version you're running. &lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2014 15:32:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123761#M9633</guid>
      <dc:creator>billford</dc:creator>
      <dc:date>2014-12-09T15:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Fortinet FortiOS 5: Is anyone else getting transforms errors "Regex: two named subpatterns have the same name"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123762#M9634</link>
      <description>&lt;P&gt;I have installed 6.2 on windows 8&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2014 18:20:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123762#M9634</guid>
      <dc:creator>fortinet</dc:creator>
      <dc:date>2014-12-17T18:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Fortinet FortiOS 5: Is anyone else getting transforms errors "Regex: two named subpatterns have the same name"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123763#M9635</link>
      <description>&lt;P&gt;I can't imagine Windows making any difference, I might try that though&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2014 18:22:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123763#M9635</guid>
      <dc:creator>billford</dc:creator>
      <dc:date>2014-12-17T18:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Fortinet FortiOS 5: Is anyone else getting transforms errors "Regex: two named subpatterns have the same name"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123764#M9636</link>
      <description>&lt;P&gt;Hi there,&lt;BR /&gt;
There is a new version on the app. Please check if this solves your problems.&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Open3S.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Feb 2015 15:22:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123764#M9636</guid>
      <dc:creator>open3s</dc:creator>
      <dc:date>2015-02-25T15:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for Fortinet FortiOS 5: Is anyone else getting transforms errors "Regex: two named subpatterns have the same name"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123765#M9637</link>
      <description>&lt;P&gt;I have installed the new version &lt;/P&gt;

&lt;P&gt;I am having the same issue in 5 of my default transforms&lt;/P&gt;

&lt;P&gt;Bad regex value: [Regex] , of param: transforms.conf / [stanza below] / REGEX; why: two named subpatterns have the same name&lt;/P&gt;

&lt;P&gt;[extract_event_his-performancev5]&lt;BR /&gt;
[extract_ipsv5]&lt;BR /&gt;
[extract_trafficv5]&lt;BR /&gt;
[extract_virusv5]&lt;BR /&gt;
[extract_webfilterv5]&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:12:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-for-Fortinet-FortiOS-5-Is-anyone-else-getting-transforms/m-p/123765#M9637</guid>
      <dc:creator>mad4wknds</dc:creator>
      <dc:date>2020-09-29T08:12:16Z</dc:date>
    </item>
  </channel>
</rss>

