<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: regex error in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679625#M113571</link>
    <description>&lt;P&gt;1) The limits.conf file is configured by your administrator: &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.0/admin/limitsconf#.5Brex.5D" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.0/admin/limitsconf#.5Brex.5D&lt;/A&gt;&lt;BR /&gt;2) When I search for similar questions to yours. I find some possible answers to your problem:&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Rex-has-exceeded-configured-match-limit/m-p/391837" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Rex-has-exceeded-configured-match-limit/m-p/391837&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Regex-error-exceeded-configured-match-limit/m-p/469890" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Regex-error-exceeded-configured-match-limit/m-p/469890&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Error-has-exceeded-configured-match-limit/m-p/539725" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Error-has-exceeded-configured-match-limit/m-p/539725&lt;/A&gt;&lt;BR /&gt;3) You'll notice in these other answers, that the questions supply a log sample and their query to show what the rex is working against. Only do this if the event information is not sensitive. But without that information, it'll be difficult for the community to help you. That's why I'm supplying you with some other information too.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2024 18:06:50 GMT</pubDate>
    <dc:creator>efavreau</dc:creator>
    <dc:date>2024-03-05T18:06:50Z</dc:date>
    <item>
      <title>regex error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679611#M113563</link>
      <description>&lt;P&gt;Hi Team,&lt;BR /&gt;While running the query I'm able see this error.&lt;BR /&gt;but how to overcome this I have tried with spath command, but it does not work.&lt;BR /&gt;I have attached screen shot for the same. Please could you help on this asap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="prasireddy_0-1709654012876.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29597iD2D37D060DB49D8B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="prasireddy_0-1709654012876.png" alt="prasireddy_0-1709654012876.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks Advance&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 15:55:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679611#M113563</guid>
      <dc:creator>prasireddy</dc:creator>
      <dc:date>2024-03-05T15:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: regex error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679625#M113571</link>
      <description>&lt;P&gt;1) The limits.conf file is configured by your administrator: &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.0/admin/limitsconf#.5Brex.5D" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.0/admin/limitsconf#.5Brex.5D&lt;/A&gt;&lt;BR /&gt;2) When I search for similar questions to yours. I find some possible answers to your problem:&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Rex-has-exceeded-configured-match-limit/m-p/391837" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Rex-has-exceeded-configured-match-limit/m-p/391837&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Regex-error-exceeded-configured-match-limit/m-p/469890" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Regex-error-exceeded-configured-match-limit/m-p/469890&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Error-has-exceeded-configured-match-limit/m-p/539725" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Error-has-exceeded-configured-match-limit/m-p/539725&lt;/A&gt;&lt;BR /&gt;3) You'll notice in these other answers, that the questions supply a log sample and their query to show what the rex is working against. Only do this if the event information is not sensitive. But without that information, it'll be difficult for the community to help you. That's why I'm supplying you with some other information too.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 18:06:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679625#M113571</guid>
      <dc:creator>efavreau</dc:creator>
      <dc:date>2024-03-05T18:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: regex error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679629#M113572</link>
      <description>&lt;P&gt;Your expression is matching on at least 1 word character or non-word character i.e. almost anything, it then reduces back to the fewest characters match this, i.e. 1 character, so each instance of x is now a single character. This is why you are blowing the max_match limit. Try either including a trailing anchor pattern (and removing the ?), or improving the matching pattern.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 18:46:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679629#M113572</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-03-05T18:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: regex error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679740#M113582</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&lt;BR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/88735"&gt;@efavreau&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Actually present I'm using this regex in query&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;| rex field=_raw ""requestId"(?&amp;lt;x&amp;gt;[\w\W]+?)]"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My raw data is json format&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;"batchId" : "63361",&lt;/P&gt;&lt;P&gt;&amp;nbsp; "internalFWDLRequestId" : "70-B3-D5-1F-30-5F-30-00:70-B3-D5-1F-30-00-A0-03:519633036",&lt;/P&gt;&lt;P&gt;&amp;nbsp; "initialJobId" : 3860464,&lt;/P&gt;&lt;P&gt;&amp;nbsp; "batchCreationDate" : 1709203012824,&lt;/P&gt;&lt;P&gt;&amp;nbsp; "batchSubmissionDate" : 1709293013333,&lt;/P&gt;&lt;P&gt;&amp;nbsp; "allowMultipleRequests" : true,&lt;/P&gt;&lt;P&gt;&amp;nbsp; "abortedCountForDuplicateRepId" : 0,&lt;/P&gt;&lt;P&gt;&amp;nbsp; "abortedDuplicatesJobId" : null,&lt;/P&gt;&lt;P&gt;&amp;nbsp; "image" : {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "approvedFirmwareVersionId" : "00070400",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "fileName" : "00070400",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "imageByteCount" : 663191,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "mfcImageThumbprint" : "663125_675428228_vQhOAh27O+KHxkpO/Qrq0g=="&lt;/P&gt;&lt;P&gt;&amp;nbsp; },&lt;/P&gt;&lt;P&gt;&amp;nbsp; "serviceUserRequests" : [ {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "requestId" : "70-B3-D5-1F-30-5F-30-00:70-B3-D5-1F-30-00-A0-03:519633036",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "requestDate" : 1709203013315,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "imageCRC" : 2291340038,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "numberOfCommsHubs" : 3,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; "deliveryPoints" : [ {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "commsHubId" : 101388585,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "endpointId" : "00-1D-24-02-01-0B-11-8E"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }, {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "commsHubId" : 101762268,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "endpointId" : "00-1D-24-02-01-0A-D0-81"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }, {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "commsHubId" : 102016271,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "endpointId" : "00-1D-24-02-01-0A-CF-75"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; } ]&lt;/P&gt;&lt;P&gt;&amp;nbsp; } ],&lt;/P&gt;&lt;P&gt;&amp;nbsp; "endpointType" : 1&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 09:03:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679740#M113582</guid>
      <dc:creator>prasireddy</dc:creator>
      <dc:date>2024-03-06T09:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: regex error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679753#M113584</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "\"requestId\"\s:\s\"(?&amp;lt;x&amp;gt;[^\"]+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 06 Mar 2024 10:09:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679753#M113584</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-03-06T10:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: regex error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679757#M113585</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Its not working&amp;nbsp; which you have shared in my query&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 10:15:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679757#M113585</guid>
      <dc:creator>prasireddy</dc:creator>
      <dc:date>2024-03-06T10:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: regex error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679758#M113586</link>
      <description>&lt;P&gt;Here is a runanywhere example using the example you posted showing the extract working. If the sample data does not match your events sufficiently closely enough, please post a more accurate representation of your raw events, preferably in a code block &amp;lt;/&amp;gt; similar to how I have done.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| fields - _time
| eval _raw="{\"batchId\" : \"63361\",

  \"internalFWDLRequestId\" : \"70-B3-D5-1F-30-5F-30-00:70-B3-D5-1F-30-00-A0-03:519633036\",

  \"initialJobId\" : 3860464,

  \"batchCreationDate\" : 1709203012824,

  \"batchSubmissionDate\" : 1709293013333,

  \"allowMultipleRequests\" : true,

  \"abortedCountForDuplicateRepId\" : 0,

  \"abortedDuplicatesJobId\" : null,

  \"image\" : {

    \"approvedFirmwareVersionId\" : \"00070400\",

    \"fileName\" : \"00070400\",

    \"imageByteCount\" : 663191,

    \"mfcImageThumbprint\" : \"663125_675428228_vQhOAh27O+KHxkpO/Qrq0g==\"

  },

  \"serviceUserRequests\" : [ {

    \"requestId\" : \"70-B3-D5-1F-30-5F-30-00:70-B3-D5-1F-30-00-A0-03:519633036\",

    \"requestDate\" : 1709203013315,

    \"imageCRC\" : 2291340038,

    \"numberOfCommsHubs\" : 3,

    \"deliveryPoints\" : [ {

      \"commsHubId\" : 101388585,

      \"endpointId\" : \"00-1D-24-02-01-0B-11-8E\"

    }, {

      \"commsHubId\" : 101762268,

      \"endpointId\" : \"00-1D-24-02-01-0A-D0-81\"

    }, {

      \"commsHubId\" : 102016271,

      \"endpointId\" : \"00-1D-24-02-01-0A-CF-75\"

    } ]

  } ],

  \"endpointType\" : 1}"
| rex field=_raw "\"requestId\"\s:\s\"(?&amp;lt;x&amp;gt;[^\"]+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 06 Mar 2024 10:18:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679758#M113586</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-03-06T10:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: regex error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679760#M113587</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually this is my query&lt;BR /&gt;&lt;BR /&gt;index=fwdl-meter-batching-agent-logs earliest=-7d@h-5d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;| rex field=_raw ""requestId"(?&amp;lt;x&amp;gt;[\w\W]+?)]" max_match=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;| table internalFWDLRequestId x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;| mvexpand x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;| rex field=x "\"commsHubId\"\s+:\s+(?&amp;lt;CH_ID&amp;gt;\d+)" max_match=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;| rex field=x "^\" : \"(?&amp;lt;suRequestId&amp;gt;.+?)\""&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;| mvexpand CH_ID&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;| rename internalFWDLRequestId as requestId&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;| eval x=requestId."-".CH_ID&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;| fields x suRequestId&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 10:25:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679760#M113587</guid>
      <dc:creator>prasireddy</dc:creator>
      <dc:date>2024-03-06T10:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: regex error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679762#M113589</link>
      <description>&lt;P&gt;Since this looks like JSON, why not use spath? Try something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath serviceUserRequests{} output=serviceUserRequests
| mvexpand serviceUserRequests&lt;/LI-CODE&gt;&lt;P&gt;Obviously you will have to modify the paths to fit your actual events.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 10:44:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex-error/m-p/679762#M113589</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-03-06T10:44:04Z</dc:date>
    </item>
  </channel>
</rss>

