Splunk Dev

specified a regex without any named capturing group

biagiodipalma
Explorer

Hi there,

App Inspect v. 2.4.0.dev13 gives me this failure:

[TRANSFORMS-extract-fields] setting in props.conf specified a regex without any named capturing group. This is an incorrect usage. Please include at least one named capturing group. File: default/props.conf Line Number: 2

The regex affected are:

 

 

[extract-queue-statistics]
REGEX = ^.*rsyslogd-pstats\:\sim(?P<protocol>\w+)\W+(?P<port>\d+)\W\:\ssubmitted=(?P<submitted>\d+).*$

[extract-port-submitted]
REGEX = ^.*rsyslogd-pstats\:\s(?P<queue>[^:]+)\:\ssize=(?P<size>\d+)\senqueued=(?P<enqueued>\d+)\sfull=(?P<full>\d+)\sdiscarded\.full=(?P<discarded_full>\d+)\sdiscarded\.nf=(?P<discarded_nf>\d+)\smaxqsize=(?P<maxqsize>\d+).*$

 

How could I pass validation? I need to deploy this app on Splunk Cloud.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...