Splunk Search

Why am I always getting an error when finishing an extraction of new fields using the Field Extractor utility in Splunk 6.2?

StijnJans
New Member

In version 6.2 adding new fields via the wizard always results in this error:
In handler 'props-extract': Argument 'value' contains invalid character. e.g. for regex : ^(?:[^\|\n]*\|){4}\s+(?P[^ ]+)[^\]\n]*\]\s+\[(?P[^\]]+)

Anyone any idea what is causing this? Tnx!

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

There appears to be a unicode escape character (U+001B) in your regex...?

alt text

0 Karma
Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...