Splunk Search

Why am I always getting an error when finishing an extraction of new fields using the Field Extractor utility in Splunk 6.2?

StijnJans
New Member

In version 6.2 adding new fields via the wizard always results in this error:
In handler 'props-extract': Argument 'value' contains invalid character. e.g. for regex : ^(?:[^\|\n]*\|){4}\s+(?P[^ ]+)[^\]\n]*\]\s+\[(?P[^\]]+)

Anyone any idea what is causing this? Tnx!

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

There appears to be a unicode escape character (U+001B) in your regex...?

alt text

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...