All Apps and Add-ons

JMS Messaging Modular Input: Why am I receiving "ERROR Regex - Failed in pcre_exec" errors after upgrading the Splunk forwarder?

skuma30
New Member

HI,
I'm receiving bunch of errors in the splunkd.log referring to JMS Messaging Modular Input (jms_ta) but I updated the add-on but some reason the jms_ta has stopped polling the logs from the queue which we are supposed to get in the old add-on. So I degraded the add-on to the old version.
ex errors:-

04-20-2017 10:01:58.488 -0500 ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: (?im).*
04-20-2017 10:01:58.957 -0500 ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: (?im).*
04-20-2017 10:01:59.733 -0500 ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: (?im).*
04-20-2017 10:02:00.179 -0500 ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: (?im).*

Can you please help me

0 Karma

skuma30
New Member

@Damien Dallimore please find the below conf files in my system:-
inputs:-
[tcp-ssl://6514]
connection_host = dns
index = network
sourcetype = cisco_udp
disabled = 0
Props:-
[mq]
TRUNCATE=0

[log4j]
TRUNCATE=0

And I dont have any transforms file.
Please review and find me a solution for this.

0 Karma

Damien_Dallimor
Ultra Champion

Can you throughly describe you setup and confguration ? props.conf , transforms.conf , inputs.conf etc.....

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...