Closed Suirand1 closed 2 years ago
I did modified props.conf
- EVAL-target_process_name = case(EventCode=="6","System",EventCode=="8" OR EventCode=="10"),replace(TargetImage,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)",""),1==1,"")
+ EVAL-target_process_name = case(EventCode=="6","System",EventCode=="8" OR EventCode=="10",replace(TargetImage,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)",""),1==1,"")
error is gone now
thanks ( very late) I fixed it!
I am getting some warnings in splunkd.log every half an hour.
CalcFieldProcessor - Invalid eval expression for 'EVAL-target_process_name' in stanza [source::XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]: The operator at ',replace(TargetImage,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)",""),1==1,"")' is invalid.