<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\= in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452321#M128067</link>
    <description>&lt;P&gt;Are you using this regex on the search bar with the rex command? If so, you have to use max_match.&lt;/P&gt;

&lt;P&gt;The default for max_match is 1. Your regex is matching more than one value in an event. &lt;/P&gt;

&lt;P&gt;Set max_match=0 for unlimited matches.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Mar 2019 19:02:03 GMT</pubDate>
    <dc:creator>bcyates</dc:creator>
    <dc:date>2019-03-21T19:02:03Z</dc:date>
    <item>
      <title>ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452319#M128065</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am getting this error in search head don't know why. Anybody had same issue please let me know.&lt;/P&gt;

&lt;P&gt;Thansk.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 14:38:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452319#M128065</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2019-03-21T14:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452320#M128066</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Can you please provide some sample data (Mask sensitive data) and regex ?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 14:50:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452320#M128066</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-03-21T14:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452321#M128067</link>
      <description>&lt;P&gt;Are you using this regex on the search bar with the rex command? If so, you have to use max_match.&lt;/P&gt;

&lt;P&gt;The default for max_match is 1. Your regex is matching more than one value in an event. &lt;/P&gt;

&lt;P&gt;Set max_match=0 for unlimited matches.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 19:02:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452321#M128067</guid>
      <dc:creator>bcyates</dc:creator>
      <dc:date>2019-03-21T19:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452322#M128068</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Thanks for the reply but i am not using any regex which has that field. I checked everything on the search head.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 19:34:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452322#M128068</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2019-03-21T19:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452323#M128069</link>
      <description>&lt;P&gt;Same error here.&lt;BR /&gt;
I can reproduce this error each time i refresh the job manager page&lt;BR /&gt;
Splunk 7.2.5&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 08:58:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452323#M128069</guid>
      <dc:creator>C_HIEN</dc:creator>
      <dc:date>2019-03-29T08:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452324#M128070</link>
      <description>&lt;P&gt;max_match is not really related to that error and will not solve it. If you get such an error when running regexes, it means your regex is poorly written and has too many matches (usually because of using stuff like &lt;CODE&gt;.*&lt;/CODE&gt; and &lt;CODE&gt;.*?&lt;/CODE&gt;, which cause the regex to match the string in many ways and require a lot of backtracking in the regex engine.&lt;BR /&gt;
The solution is to write a better regex.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 09:09:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452324#M128070</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-29T09:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452325#M128071</link>
      <description>&lt;P&gt;When / Where are you getting that error? If you're not actually doing a regex yourself, this is either a bug in splunk, or in some field extraction config or so in an add-on you have installed (although I'm not sure if that would result in errors presented in the GUI)?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 09:11:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452325#M128071</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-29T09:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452326#M128072</link>
      <description>&lt;P&gt;Thanks for your reply. I think i have one regex which is matching many fields because of logs having different log pattern. &lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 14:38:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452326#M128072</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2019-04-03T14:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452327#M128073</link>
      <description>&lt;P&gt;Did you ever figure this out? We are seeing the exact same error message in our splunkd log.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2019 17:03:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452327#M128073</guid>
      <dc:creator>robert_miller</dc:creator>
      <dc:date>2019-06-04T17:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452328#M128074</link>
      <description>&lt;P&gt;Same error for us and we are running 7.2.4.  Maybe this is an issue with 7.2.x.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2019 19:05:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452328#M128074</guid>
      <dc:creator>robert_miller</dc:creator>
      <dc:date>2019-06-04T19:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452329#M128075</link>
      <description>&lt;P&gt;When and where are you getting that error?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 12:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452329#M128075</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-06-05T12:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452330#M128076</link>
      <description>&lt;P&gt;I see this error on our SH running Enterprise Security.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 20:02:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452330#M128076</guid>
      <dc:creator>robert_miller</dc:creator>
      <dc:date>2019-06-05T20:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452331#M128077</link>
      <description>&lt;P&gt;But where and when specifically? On which page / after doing what kind of action (e.g. is it with running a specific search, or upon visiting a certain page / dashboard /...).&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 07:33:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452331#M128077</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-06-06T07:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452332#M128078</link>
      <description>&lt;P&gt;How do we fix this in the jobs page?&lt;/P&gt;

&lt;P&gt;/en-US/app/SplunkEnterpriseSecuritySuite/job_manager&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 18:27:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452332#M128078</guid>
      <dc:creator>tommoore</dc:creator>
      <dc:date>2019-06-10T18:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452333#M128079</link>
      <description>&lt;P&gt;It does appear to be when I go to the job_manager.  Looks like @tommoore and I have the same issue.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 19:05:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452333#M128079</guid>
      <dc:creator>robert_miller</dc:creator>
      <dc:date>2019-06-10T19:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452334#M128080</link>
      <description>&lt;P&gt;Sounds like a bug then, which is probably best raised with Splunk Support.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 08:00:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452334#M128080</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-06-11T08:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452335#M128081</link>
      <description>&lt;P&gt;I just heard from support about this issue, and its a known bug (internal bug SPL-160983) that they have decided to not fix.  There is no impact to the system and there isn't a way to stop the error from triggering.  Support said to ignore these errors going forward.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 17:36:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452335#M128081</guid>
      <dc:creator>robert_miller</dc:creator>
      <dc:date>2019-07-01T17:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: \|.*?summarize.*?action\=</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452336#M128082</link>
      <description>&lt;P&gt;We have the same thing here. The regex itself seems working fine. It seems just another annoying error which could be safely ignore. &lt;/P&gt;

&lt;P&gt;I think the resolution is to write a less greedy regex.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 23:31:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ERROR-Regex-Failed-in-pcre-exec-Error-PCRE-ERROR-MATCHLIMIT-for/m-p/452336#M128082</guid>
      <dc:creator>season88481</dc:creator>
      <dc:date>2019-07-23T23:31:15Z</dc:date>
    </item>
  </channel>
</rss>

