Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why is my inputlookup search suddenly producing error "regular expression is too large"?

$
0
0
We use inputlookup to run large numbers (thousands) of indicators against network traffic in our org. This has worked well for some time. [|inputlookup indicators.csv | fields foo| rename foo as search|format maxresults=10000] index=bar Recently, on another instance of Splunk I've started getting this error: > Regex: regular expression is too large To get the search to complete, I either have to remove the maxresults variable (which 'dumbs' the amount of indicators used in the search to the first 100) or change maxresults to 1000 - any larger number fails. Did something change with the way Splunk processes these types of searches?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>