splunk / splunk-connect-for-syslog

Splunk Connect for Syslog
Apache License 2.0
152 stars 107 forks source link

Multiple "Failed to JIT compile regular expression, you might want to use flags(disable-jit)" #2241

Open kobz360 opened 10 months ago

kobz360 commented 10 months ago

What is the sc4s version ? 3.4.5

Describe the bug Hi Team, I have recently upgraded our SC4S BYOE environment from 2.49.3 to 3.4.5 (along with upgrading the underlying Syslog-NG package to match what SC4S wants), however, since doing so, I have observed a range of the JIT compilation errors on startup in Journalctl. Ultimately, it does not stop the SC4S service from running, however, I suspect it may potentially be impacting the parsing or performance of the impacted parsers.

There's limited information on this online, but it looks like it may be to due with the move to PCRE2.

I will post some attachments below:

Screenshot 2023-10-17 at 11 04 07 am
rjha-splunk commented 10 months ago

We will try to replicate it.