I tracked my error down to the Splunk for unix app using btool. https://splunkbase.splunk.com/app/273/ splunk btool validate-regex Bad regex value: '(?::){0}*', of param: props.conf / [(?::){0}*]; why: this regex is likely to apply to all data and may break summary indexing, among other Splunk features. splunk btool props list --debug | find {0} Splunk\etc\apps\splunk_app_for_nix\default\props.conf [(?::){0}*]
... View more