I indexed some logs that have values are separated by commas, and I attempted to extract fields using delimiter
, but the following error was output.
regular expression is too large
Does the delimiter
extraction have limit values?
I hope someone can tell me.
Try shortening all the field names in the regex
Ex:
(?<my_long_field_name>regextoextract)
Becomes
(?<a>regextoextract)
Do that for all your field names, then rename them in search. I believe you’re hitting a validation character limit of 8096.
Thank youf for answer!
8096 means 8096 bytes?
And is it limit of splunk regex?
Can you give sample data? How many columns you are extracting?
Try extracting with transforms.conf, refer below doc:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Knowledge/Configureadvancedextractionswithfieldtra...
Thank you for comment.
I'm sorry, I can't give you sample data,but It has over 200 columns.