Installation

Issue: I haved added rex in our web data model app but it is show error

PCIIT
New Member

Hello Sir ,
I am having issue with the Splunk App for Web data model... but not sure where the problem is.
I have replaced regex in our data model .json file but it is not working.
In our data model , we have some field (date, time , decision_list) and added Rex in expression like
Rex:
"expression": "^([\w]+-)(?[\w]+[^-]+)" but it is giving error "

{
"outputFields": [
{
"fieldName": "Description",
"owner": "Event",
"type": "string",
"required": false,
"multivalue": false,
"hidden": false,
"editable": true,
"displayName": "Description",
"comment": "",
"fieldSearch": ""
}
],
"inputField": "decision_list",
"calculationID": "asdfassdfg",
"owner": "Event",
"editable": true,
"comment": "",
"calculationType": "Rex",
"expression": " ^([\w]+-)(?[\w]+[^-]+)"
},

when I am searching in Dashboard so facing Error in Dashboard :

Error:
"Error in 'PivotProcessor': Error in 'DataModelEvaluator': JSON for data model 'Web_Acc_Data' is invalid."

This regex is working perfectly in regex editor.
Someone has any clue?

Tags (1)
0 Karma

lakshman239
Influencer

I assume you are taking the standard 'Web' datamodel that comes with Splunk_SA_CIM and updating the Web.json file.

What's your use case/requirement? If you want to edit any calculated fields, you can do the same via GUI [ Settings -> Datamodels and select the datamodel, and edit it and validate them before saving it]

https://docs.splunk.com/Documentation/Splunk/7.2.3/Knowledge/Managedatamodels

0 Karma

PCIIT
New Member

we have our own web security reporting APP . it is working fine with below regex.
^([^\_\-]+)\_([^\-]+)-(?[^-]+) ----> working fine
but i have replaced with below regex which is not working
^([\w]+-)(?[\w]+[^-]+) -------> not working

i have input field decision_list which is used for output field description
here decision_list = DECR_WEB_7-webGroup-SH_Auth-DefaultGroup-NONE-NONE-DefaultGroup
description = webGroup ---->expecting field description value so write regex expression but it is not working

0 Karma
Get Updates on the Splunk Community!

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...