We are seeing the following warning message over and over:
IndexOutOfBounds invalid The FORMAT capturing group id: id=3, transform_name='error_info'
The only app that I could find that has this transform name is the Microsoft Cloud Services app. The default folder transforms.conf ha this section:
REGEX = Request\s+for\s+account=\"(.)\"\s+failed:\s+[.]\s+(?:POST|GET)\s+request\s+to\s+(.*)\s+(?:fail|failed|exception)
FORMAT = account_name::$1 url::$2 error_info::$3 account_status::"invalid"
I have no idea why this warning message pops up but it appears 4-5 times every second. We are running Splunk Enterprise 6.6.2. Thanks for any assistance.