<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does Splunk complain about a missing parenthetical? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-complain-about-a-missing-parenthetical/m-p/15877#M1843</link>
    <description>&lt;P&gt;I have heard this error can occur from a front-end error when attempting to upload certain data, via the "upload a file" interface in the web manager.   The solution to that problem was to manually add the file via CLI, or monitor the directory of the file (if possible).&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jul 2010 23:41:31 GMT</pubDate>
    <dc:creator>Simeon</dc:creator>
    <dc:date>2010-07-06T23:41:31Z</dc:date>
    <item>
      <title>Why does Splunk complain about a missing parenthetical?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-complain-about-a-missing-parenthetical/m-p/15874#M1840</link>
      <description>&lt;P&gt;This is a very vague question.  I have received a query from a partner who has observed Splunk erroring out complaining about a "missing parenthetical" when indexing web proxy logs.  I am unable to get a sample of the proxy data being indexed or a screenshot since this is part of a security investigation.  A search of "missing parenthetical" on splunk.com turns up zero results.  I am hoping someone out there has encountered this error or can review the source code and explain the conditions under which this error might occur.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2010 11:02:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-complain-about-a-missing-parenthetical/m-p/15874#M1840</guid>
      <dc:creator>hulahoop</dc:creator>
      <dc:date>2010-06-22T11:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk complain about a missing parenthetical?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-complain-about-a-missing-parenthetical/m-p/15875#M1841</link>
      <description>&lt;P&gt;This error occurs where? In the splunkd.log, the web UI, what? On the one hand, you say it happens when &lt;EM&gt;indexing&lt;/EM&gt;, but on the other hand you take about getting a screenshot rather than the log file with the error in it.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2010 23:41:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-complain-about-a-missing-parenthetical/m-p/15875#M1841</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-06-22T23:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk complain about a missing parenthetical?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-complain-about-a-missing-parenthetical/m-p/15876#M1842</link>
      <description>&lt;P&gt;And I suspect that in this game of telephone, the actual original messages complained about a missing &lt;EM&gt;parenthesis&lt;/EM&gt;, not parenthetical. I would imagine if it appears in search, the location of the problem would be obvious. The likely other place would be a misconfigured regular expression in either search-time or index-time extraction regexes.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2010 23:45:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-complain-about-a-missing-parenthetical/m-p/15876#M1842</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-06-22T23:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk complain about a missing parenthetical?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-complain-about-a-missing-parenthetical/m-p/15877#M1843</link>
      <description>&lt;P&gt;I have heard this error can occur from a front-end error when attempting to upload certain data, via the "upload a file" interface in the web manager.   The solution to that problem was to manually add the file via CLI, or monitor the directory of the file (if possible).&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2010 23:41:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-complain-about-a-missing-parenthetical/m-p/15877#M1843</guid>
      <dc:creator>Simeon</dc:creator>
      <dc:date>2010-07-06T23:41:31Z</dc:date>
    </item>
  </channel>
</rss>

