All Apps and Add-ons

JMS Messaging Modular Input: Why am I receiving "ERROR Regex - Failed in pcre_exec" errors after upgrading the Splunk forwarder?

skuma30
New Member

HI,
I'm receiving bunch of errors in the splunkd.log referring to JMS Messaging Modular Input (jms_ta) but I updated the add-on but some reason the jms_ta has stopped polling the logs from the queue which we are supposed to get in the old add-on. So I degraded the add-on to the old version.
ex errors:-

04-20-2017 10:01:58.488 -0500 ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: (?im).*
04-20-2017 10:01:58.957 -0500 ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: (?im).*
04-20-2017 10:01:59.733 -0500 ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: (?im).*
04-20-2017 10:02:00.179 -0500 ERROR Regex - Failed in pcre_exec: Error PCRE_ERROR_MATCHLIMIT for regex: (?im).*

Can you please help me

0 Karma

skuma30
New Member

@Damien Dallimore please find the below conf files in my system:-
inputs:-
[tcp-ssl://6514]
connection_host = dns
index = network
sourcetype = cisco_udp
disabled = 0
Props:-
[mq]
TRUNCATE=0

[log4j]
TRUNCATE=0

And I dont have any transforms file.
Please review and find me a solution for this.

0 Karma

Damien_Dallimor
Ultra Champion

Can you throughly describe you setup and confguration ? props.conf , transforms.conf , inputs.conf etc.....

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...