Hello,
Trying to renames fields for CIM compliance, and I see this pop up when trying to rename via deliminer. Any field I try I get this warning. Although it lets me save?
Thanks
Hi @jbender72,
I think it is complaining because of too many fields for delimiters. You can try EVAL or FIELDALIAS to create CIM compaint field on your sourcetype like below;
EVAL-src=srcip
or
FIELDALIAS-src=srcip AS src
If this reply helps you an upvote is appreciated.
That's one humungous regex! Your regex is doing a lot of lookahead/backtracking, so it's hitting the limits, see
https://docs.splunk.com/Documentation/Splunk/8.1.1/Admin/Limitsconf
options are to split up your rex or to find an more efficient way to CIM map/extract the fields 😞
That's what I mean, this just popped up out of "nowhere", looking for a solution. I will look into limits.conf thank you.
Hi @jbender72,
I think it is complaining because of too many fields for delimiters. You can try EVAL or FIELDALIAS to create CIM compaint field on your sourcetype like below;
EVAL-src=srcip
or
FIELDALIAS-src=srcip AS src
If this reply helps you an upvote is appreciated.