<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error: WinRegistryMonitor::configure: Failed to get configuration settings: 'Regex: number too big in {} quantifier' in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Error-WinRegistryMonitor-configure-Failed-to-get-configuration/m-p/594662#M103925</link>
    <description>&lt;P&gt;And that's the only inputs.conf located on your UF? Splunk-regmon is trying to be ran from some configuration. Were you actively monitoring the registry before this error started to pop up?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Take a look at this article:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/MonitorWindowsregistrydata" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/MonitorWindowsregistrydata&lt;/A&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;The inputs.conf file contains the specific regular expressions you create to refine and filter the Registry hive paths you want the Splunk platform to monitor.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It could be that the app is looking at the wrong inputs.conf and getting confused.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try running this command to look through all of your inputs.confs&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;D:\SplunkUniversalForwarder\bin\splunk.exe btool inputs list &amp;gt; ..\btool.txt&lt;/LI-CODE&gt;&lt;P&gt;It will create a txt file for you to go through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Apr 2022 12:54:29 GMT</pubDate>
    <dc:creator>Stefanie</dc:creator>
    <dc:date>2022-04-21T12:54:29Z</dc:date>
    <item>
      <title>Error: WinRegistryMonitor::configure: Failed to get configuration settings: 'Regex: number too big in {} quantifier'</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-WinRegistryMonitor-configure-Failed-to-get-configuration/m-p/594391#M103899</link>
      <description>&lt;P&gt;I found many errors from _internal log&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ERROR&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ExecProcessor&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;message&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;from&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;"&lt;/SPAN&gt;&lt;SPAN&gt;D:\SplunkUniversalForwarder\bin\splunk-regmon.exe&lt;/SPAN&gt;&lt;SPAN&gt;"&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;splunk-regmon&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;WinRegistryMonitor::configure:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Failed&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;to&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;get&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;configuration&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;settings:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;'&lt;/SPAN&gt;&lt;SPAN&gt;Regex:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;number&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;too&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;big&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;in&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;{}&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;quantifier'&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Any ideas how to resolve this error?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 15:55:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-WinRegistryMonitor-configure-Failed-to-get-configuration/m-p/594391#M103899</guid>
      <dc:creator>nareerat_pr</dc:creator>
      <dc:date>2022-04-20T15:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: Error: WinRegistryMonitor::configure: Failed to get configuration settings: 'Regex: number too big in {} quantifier'</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-WinRegistryMonitor-configure-Failed-to-get-configuration/m-p/594526#M103910</link>
      <description>&lt;P&gt;Do you have any REGEX in your inputs.conf ? That's where I would look first.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 18:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-WinRegistryMonitor-configure-Failed-to-get-configuration/m-p/594526#M103910</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-04-20T18:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Error: WinRegistryMonitor::configure: Failed to get configuration settings: 'Regex: number too big in {} quantifier'</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-WinRegistryMonitor-configure-Failed-to-get-configuration/m-p/594630#M103919</link>
      <description>&lt;P&gt;there are no any REGEX&lt;/P&gt;&lt;P&gt;this is my inputs.conf on uf&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nareerat_pr_0-1650535329103.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19176i2AA52495F9D41EAE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nareerat_pr_0-1650535329103.png" alt="nareerat_pr_0-1650535329103.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 10:02:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-WinRegistryMonitor-configure-Failed-to-get-configuration/m-p/594630#M103919</guid>
      <dc:creator>nareerat_pr</dc:creator>
      <dc:date>2022-04-21T10:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: Error: WinRegistryMonitor::configure: Failed to get configuration settings: 'Regex: number too big in {} quantifier'</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-WinRegistryMonitor-configure-Failed-to-get-configuration/m-p/594662#M103925</link>
      <description>&lt;P&gt;And that's the only inputs.conf located on your UF? Splunk-regmon is trying to be ran from some configuration. Were you actively monitoring the registry before this error started to pop up?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Take a look at this article:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/MonitorWindowsregistrydata" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/MonitorWindowsregistrydata&lt;/A&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;The inputs.conf file contains the specific regular expressions you create to refine and filter the Registry hive paths you want the Splunk platform to monitor.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It could be that the app is looking at the wrong inputs.conf and getting confused.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try running this command to look through all of your inputs.confs&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;D:\SplunkUniversalForwarder\bin\splunk.exe btool inputs list &amp;gt; ..\btool.txt&lt;/LI-CODE&gt;&lt;P&gt;It will create a txt file for you to go through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 12:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-WinRegistryMonitor-configure-Failed-to-get-configuration/m-p/594662#M103925</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-04-21T12:54:29Z</dc:date>
    </item>
  </channel>
</rss>

