Monitoring Splunk

Can we be alerted when a field extraction fails because of depth_limit ?

performancemoni
Path Finder

Hello everyone,

We have configured some automatic field extractions using regular expressions on some logs that can get really big. These field extractions are very important, if they fail we are missing critical information in our daily monitoring. At some point the field extraction didn't work and we realized that was because of the regex depth limit, when we ran it manually with rex and we got

 

 

Streamed search execute failed because: Error in 'rex' command: regex="<the_regex>" has exceeded the configured depth_limit, consider raising the value in limits.conf.

 

 

We fixed it by optimizing the regex and now it's working fine.

But we cannot be sure that the issue has been absolutely fixed, it could potentially happen again in the future. We would like to configure a Splunk alert that warns us when this type of error occurs. Does Splunk log anything about this type of error ? We could not find anything in _internal or anywhere else, or maybe we didn't look correctly ?

Thank you for your help !

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...