event without issue " btoolTag = btool_validate_strptime" [
{
"bad_strptime": "%d.%m.%Y %H:%M:%S,%3",
"conf_file": "props.conf",
"stanza": "lb:logs",
"attribute": "TIME_FORMAT",
"btoolTag": "btool_validate_strptime",
"timestamp": "2024-08-29T06:00:04",
"host": "blabla_hostname"
},
{
"bad_strptime": "%y-%m-%d %H:%M:%S%",
"conf_file": "props.conf",
"stanza": "iislogs",
"attribute": "TIME_FORMAT",
"btoolTag": "btool_validate_strptime",
"timestamp": "2024-08-29T06:00:04",
"host": "blabla_hostname"
}
] affected event " btoolTag = btool_validate_regex" [
{
"bad_regex": "(?i)id_618_(?<eventfield_1>\\\\w*).*i_Media=MEDIA_(?<eventfield_2>\\\\w*).*i_Dnbits=(?<eventfield_3\\\\w*).*cs_PERString=(?<eventfield_4>\\\\w*)",
"conf_file": "props.conf",
"stanza": "fansfms:aaio",
"attribute": "EXTRACT-AoIP_message1",
"reason": "syntax error in subpattern name (missing terminator?)",
"btoolTag": "btool_validate_regex",
"timestamp": "2024-08-29T09:47:46",
"host": "blabla_hostname"
},
{
"bad_regex": "([\\i\\\\fr\\n]+---splunk-admon-end-of-event---\\r\\n[\\r\\n]*)",
"conf_file": "props.conf",
"stanza": "source::(....(config|conf|cfg|inii|cfg|emacs|ini|license|lng|plist|presets|properties|props|vim|wsdl))",
"attribute": "LINE_BREAKER",
"reason": "unrecognized character follows \\",
"btoolTag": "btool_validate_regex",
"timestamp": "2024-08-29T09:47:46",
"host": "blabla_hostname"
}
]
... View more