Trying to renames fields for CIM compliance, and I see this pop up when trying to rename via deliminer. Any field I try I get this warning. Although it lets me save?
I think it is complaining because of too many fields for delimiters. You can try EVAL or FIELDALIAS to create CIM compaint field on your sourcetype like below;
FIELDALIAS-src=srcip AS src
If this reply helps you an upvote is appreciated.
View solution in original post
That's one humungous regex! Your regex is doing a lot of lookahead/backtracking, so it's hitting the limits, see
options are to split up your rex or to find an more efficient way to CIM map/extract the fields 😞
That's what I mean, this just popped up out of "nowhere", looking for a solution. I will look into limits.conf thank you.