<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rex error while field extraction -  has exceeded the configured depth_limit, consider raising the value in limits.co in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614937#M14030</link>
    <description>&lt;P&gt;it didn't worked XD..&lt;/P&gt;&lt;P&gt;let me brief in detail !!&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Look at the Sample log:&lt;/P&gt;&lt;P&gt;Event1: test="2",hi="hi",splunk="siem",best="you",Karma="sure",thank="you"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Event2:&amp;nbsp; test="2",hi="hi",field="keypair",splunk="siem",best="you",Karma="sure",thank="you"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;if trying to extracting the field Splunk (set as required) with its value "siem" from the above log&lt;/P&gt;&lt;P&gt;the field is perfectly extracted in event 1with its correct value siem but in the second event the field&amp;nbsp; splunk is extracted where the value is keypair not siem...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;A class="" href="https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614930#" target="_blank" rel="noopener"&gt;Add tags&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Sep 2022 09:51:26 GMT</pubDate>
    <dc:creator>restinlinux</dc:creator>
    <dc:date>2022-09-28T09:51:26Z</dc:date>
    <item>
      <title>Rex error while field extraction -  has exceeded the configured depth_limit, consider raising the value in limits.conf.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614856#M14022</link>
      <description>&lt;P&gt;Rex error while extracting fields with delimiter Commas...&lt;/P&gt;&lt;P&gt;For lot of the field it is NULL ( field1=NULL , field2=Null ...field4=value..)&lt;/P&gt;&lt;P&gt;Why is rex error is occuring !&lt;/P&gt;&lt;P&gt;Error message : has exceeded the configured depth_limit, consider raising the value in limits.conf.&lt;/P&gt;&lt;P&gt;whats the solution to resolve this !!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 05:14:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614856#M14022</guid>
      <dc:creator>restinlinux</dc:creator>
      <dc:date>2022-09-28T05:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Rex error while field extraction -  has exceeded the configured depth_limit, consider raising the value in limits.co</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614890#M14026</link>
      <description>&lt;P&gt;What is the configuration you are using?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 07:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614890#M14026</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-28T07:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Rex error while field extraction -  has exceeded the configured depth_limit, consider raising the value in limits.co</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614926#M14027</link>
      <description>&lt;P&gt;I have integrated some log in Splunk...&lt;/P&gt;&lt;P&gt;Need to extract the fields&lt;/P&gt;&lt;P&gt;The log has two different set of&amp;nbsp; events&lt;/P&gt;&lt;P&gt;Using the Regular expression i have tried to extract the field ..&lt;/P&gt;&lt;P&gt;the Regular expression pick the field name and the value correctly on one set of events..&lt;/P&gt;&lt;P&gt;but for the another set of event the expected field name and value is not extracting properly.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sample log:&lt;/P&gt;&lt;P&gt;test="2",hi="hi",splunk="siem",best="you",Karma="sure",thank="you"&lt;BR /&gt;test="2",hi="hi",field="keypair",splunk="siem",best="you",Karma="sure",thank="you"&lt;BR /&gt;test="2",hi="hi",splunk="siem",best="you",Karma="sure",thank="you"&lt;BR /&gt;test="2",hi="hi",splunk="siem",best="you",Karma="sure",thank="you"&lt;BR /&gt;test="2",hi="hi",splunk="siem",best="you",Karma="sure",thank="you"&lt;BR /&gt;test="2",hi="hi",splunk="siem",best="you",Karma="sure",thank="you"&lt;BR /&gt;test="2",hi="hi",field="keypair",splunk="siem",best="you",Karma="sure",thank="you"&lt;BR /&gt;test="2",hi="hi",field="keypair",splunk="siem",best="you",Karma="sure",thank="you"&lt;BR /&gt;test="2",hi="hi",field="keypair",splunk="siem",best="you",Karma="sure",thank="you"&lt;BR /&gt;test="2",hi="hi",field="keypair",splunk="siem",best="you",Karma="sure",thank="you"&lt;BR /&gt;test="2",hi="hi",splunk="siem",best="you",Karma="sure",thank="you"&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:23:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614926#M14027</guid>
      <dc:creator>restinlinux</dc:creator>
      <dc:date>2022-09-28T09:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Rex error while field extraction -  has exceeded the configured depth_limit, consider raising the value in limits.co</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614930#M14028</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Please try this:&lt;BR /&gt;| extract pairdelim="\"{,}" kvdelim=":"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:38:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614930#M14028</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2022-09-28T09:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: Rex error while field extraction -  has exceeded the configured depth_limit, consider raising the value in limits.co</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614934#M14029</link>
      <description>&lt;P&gt;What is the regex you are using?&lt;/P&gt;&lt;P&gt;Which log events are not being extracted correctly?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:49:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614934#M14029</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-28T09:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Rex error while field extraction -  has exceeded the configured depth_limit, consider raising the value in limits.co</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614937#M14030</link>
      <description>&lt;P&gt;it didn't worked XD..&lt;/P&gt;&lt;P&gt;let me brief in detail !!&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Look at the Sample log:&lt;/P&gt;&lt;P&gt;Event1: test="2",hi="hi",splunk="siem",best="you",Karma="sure",thank="you"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Event2:&amp;nbsp; test="2",hi="hi",field="keypair",splunk="siem",best="you",Karma="sure",thank="you"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;if trying to extracting the field Splunk (set as required) with its value "siem" from the above log&lt;/P&gt;&lt;P&gt;the field is perfectly extracted in event 1with its correct value siem but in the second event the field&amp;nbsp; splunk is extracted where the value is keypair not siem...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;A class="" href="https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614930#" target="_blank" rel="noopener"&gt;Add tags&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:51:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614937#M14030</guid>
      <dc:creator>restinlinux</dc:creator>
      <dc:date>2022-09-28T09:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: Rex error while field extraction -  has exceeded the configured depth_limit, consider raising the value in limits.co</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614955#M14031</link>
      <description>&lt;P&gt;sorry, pls try this:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;| extract pairdelim="\"{,}" kvdelim="="&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 10:26:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Rex-error-while-field-extraction-has-exceeded-the-configured/m-p/614955#M14031</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2022-09-28T10:26:33Z</dc:date>
    </item>
  </channel>
</rss>

