All Apps and Add-ons

Splunk for Fortinet FortiOS 5: Is anyone else getting transforms errors "Regex: two named subpatterns have the same name"?

billford
Path Finder

Anyone else getting Regex: two named subpatterns have the same name. Bad regex for the field extractions in this app? I'm having a day so I want to be sure it isn't just me.

Regex: two named subpatterns have the same name.  Bad regex: (devname\=(?\S+)|clusterid\=(?\S+)) devid\=(?\S+) logid\=(?\S+) (type\=app-ctrl|subtype\=(?\S+)) (subtype\=(?\S+)|type\=app-ctrl) (timestamp=(?\S+) |)pri\=(?\S+) (user=(?\S+) group=(?\S+) profile=(?\S+) srcip\=(?\S+) srcport\=(?\S+) srcintf\=(?\S+) dstip\=(?\S+) dstport\=(?\S+) dstintf\=(?\S+) src_name=(?\S+) dst_name\=(?\S+) proto\=(?\S+) service\=(?\S+) policyid\=(?\S+) serial\=(?\S+) applist\=(?\S+) apptype\=(?\S+) app=(?\S+) action=(?\S+) count=(?\S+) filesize=(?\S+) msg\="(?[^\"]+)" vd=(?\S+) attackid=(?\S+) profiletype=(?\S+) profilegroup=(?\S+) identidx\=(?\S+) hostname\=(?\S+) url\=(?\S+)|vd\="(?[^\"]+)" attackid\=(?\S+) user\="(?[^\"]+)" group="(?[^\"]+)" srcip\=(?\S+) srcport\=(?\S+) srcintf\="(?[^\"]+)" dstip\=(?\S+) dstport\=(?\S+) dstintf\="(?[^\"]+)" src_name\="(?[^\"]+)" dst_name\="(?[^\"]+)" profilegroup\="(?[^\"]+)" profiletype\="(?[^\"]+)" profile\="(?[^\"]+)" proto\=(?\S+) service\=(?\S+) policyid\=(?\S+) identidx\=(?\S+) serial\=(?\S+) applist\="(?[^\"]+)" apptype\="(?[^\"]+)" app\="(?[^\"]+)" action\=(?\S+) count\=(?\S+) hostname\=(?\S+) url\=(?\S+) msg\="(?[^\"]+)")
            Config problem: invalid regex: transforms.conf / [extract_app-ctrlv5] / REGEX

Over and over again for each extract. I'm running 6.1.4, thanks in advance.

Bill

0 Karma

open3s
Explorer

Hi there,
There is a new version on the app. Please check if this solves your problems.
Thanks,
Open3S.

0 Karma

mad4wknds
Path Finder

I have installed the new version

I am having the same issue in 5 of my default transforms

Bad regex value: [Regex] , of param: transforms.conf / [stanza below] / REGEX; why: two named subpatterns have the same name

[extract_event_his-performancev5]
[extract_ipsv5]
[extract_trafficv5]
[extract_virusv5]
[extract_webfilterv5]

0 Karma

fortinet
New Member

i have started using it since last few days. no error so far....

0 Karma

billford
Path Finder

I can't imagine Windows making any difference, I might try that though

0 Karma

fortinet
New Member

I have installed 6.2 on windows 8

0 Karma

billford
Path Finder

I've installed it on an empty 6.1.4, 6.1.5 and 6.2 splunk (empty as in fresh install) and I get the same errors. I actually reworked it to not get the errors and to be CIM-compliant so my issue is resolved but I'm curious what version you're running.

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...