Getting Data In

Why does Splunk complain about a missing parenthetical?

hulahoop
Splunk Employee
Splunk Employee

This is a very vague question. I have received a query from a partner who has observed Splunk erroring out complaining about a "missing parenthetical" when indexing web proxy logs. I am unable to get a sample of the proxy data being indexed or a screenshot since this is part of a security investigation. A search of "missing parenthetical" on splunk.com turns up zero results. I am hoping someone out there has encountered this error or can review the source code and explain the conditions under which this error might occur.

Tags (3)
1 Solution

Simeon
Splunk Employee
Splunk Employee

I have heard this error can occur from a front-end error when attempting to upload certain data, via the "upload a file" interface in the web manager. The solution to that problem was to manually add the file via CLI, or monitor the directory of the file (if possible).

View solution in original post

Simeon
Splunk Employee
Splunk Employee

I have heard this error can occur from a front-end error when attempting to upload certain data, via the "upload a file" interface in the web manager. The solution to that problem was to manually add the file via CLI, or monitor the directory of the file (if possible).

gkanapathy
Splunk Employee
Splunk Employee

And I suspect that in this game of telephone, the actual original messages complained about a missing parenthesis, not parenthetical. I would imagine if it appears in search, the location of the problem would be obvious. The likely other place would be a misconfigured regular expression in either search-time or index-time extraction regexes.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

This error occurs where? In the splunkd.log, the web UI, what? On the one hand, you say it happens when indexing, but on the other hand you take about getting a screenshot rather than the log file with the error in it.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...