<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to escape double quotes in a Dashboard? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97737#M5385</link>
    <description>&lt;P&gt;@drainy&lt;/P&gt;

&lt;P&gt;Non Function error : &amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&amp;lt;env:Envelope xmlns:env="&lt;A href="http://schemas.x"&gt;http://schemas.x&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;im displaying this under field msg.Im passing this value in drilldown search as msg="$click.fields.msg$". Now my search is failing with "unbalanced quote" error&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jul 2013 12:07:37 GMT</pubDate>
    <dc:creator>ma_anand1984</dc:creator>
    <dc:date>2013-07-17T12:07:37Z</dc:date>
    <item>
      <title>How to escape double quotes in a Dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97732#M5380</link>
      <description>&lt;P&gt;In my dashboard, i display log messages in a table. There are logs which has double quotes. I use custom drilldown to goto search app.&lt;/P&gt;

&lt;P&gt;Now when i click messages with double quotes, I get unbalanced quotes error. I can escape in search app with a slash and it works. But if i use eval - replace in my dashboard to add a slash, that slash is escaped automatically by splunk and i get \" instead of \".&lt;/P&gt;

&lt;P&gt;I know i can remove double quotes in my dashboard to make it work, but im looking to escape the quotes in-order to show users accurate error messages&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2013 06:54:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97732#M5380</guid>
      <dc:creator>ma_anand1984</dc:creator>
      <dc:date>2013-07-17T06:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to escape double quotes in a Dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97733#M5381</link>
      <description>&lt;P&gt;note: im using SimpleResultsTable with &lt;BR /&gt;
$click.fields.field_name$&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2013 07:16:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97733#M5381</guid>
      <dc:creator>ma_anand1984</dc:creator>
      <dc:date>2013-07-17T07:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to escape double quotes in a Dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97734#M5382</link>
      <description>&lt;P&gt;have u tried extract field option?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2013 07:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97734#M5382</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2013-07-17T07:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to escape double quotes in a Dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97735#M5383</link>
      <description>&lt;P&gt;create a proper REGEX for the items inside the "" and extract the value&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2013 07:32:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97735#M5383</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2013-07-17T07:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to escape double quotes in a Dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97736#M5384</link>
      <description>&lt;P&gt;Could you post a couple of example events?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2013 09:32:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97736#M5384</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2013-07-17T09:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to escape double quotes in a Dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97737#M5385</link>
      <description>&lt;P&gt;@drainy&lt;/P&gt;

&lt;P&gt;Non Function error : &amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&amp;lt;env:Envelope xmlns:env="&lt;A href="http://schemas.x"&gt;http://schemas.x&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;im displaying this under field msg.Im passing this value in drilldown search as msg="$click.fields.msg$". Now my search is failing with "unbalanced quote" error&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2013 12:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97737#M5385</guid>
      <dc:creator>ma_anand1984</dc:creator>
      <dc:date>2013-07-17T12:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to escape double quotes in a Dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97738#M5386</link>
      <description>&lt;P&gt;Use &amp;amp;quot instead of the quote in your search expression in xml&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2013 12:22:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97738#M5386</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2013-07-17T12:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to escape double quotes in a Dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97739#M5387</link>
      <description>&lt;P&gt;Splunk's SimpleResultsTable and JSChart/FlashChart modules don't have any mechanism to escape either backslashes or double-quotes automatically for drilldowns.  So for those modules drilldowns on such tokens as &lt;CODE&gt;C:\foo\bar\baz&lt;/CODE&gt;  as well as &lt;CODE&gt;this "has some doublequotes" in it&lt;/CODE&gt; will end up searching on the wrong thing or will fail with parse errors.  &lt;/P&gt;

&lt;P&gt;Sideview Utils, which you're using here (I can tell from $click.fields.msg$ as well as from knowing you from lots of previous questions/emails), does a lot of careful work and patches to provide a consistent $click.fields.fieldName$ key that is backslash-escaped,  and a $click.fields.fieldName.rawValue$ key that is not.   (in general for every Sideview key that might be destined for the search language, and that comes from user input or from a field value in search results, there will be a &lt;CODE&gt;*.rawValue&lt;/CODE&gt; $foo$ token as well.  the normal escaped key is for anything that goes directly into search language.  The &lt;CODE&gt;*.rawValue&lt;/CODE&gt; equivalent is what you should use for redirects, URL arguments, and to display HTML to the user.)&lt;/P&gt;

&lt;P&gt;Unfortunately there's an oversight in the Sideview code.  While it very carefully escapes backslash characters correctly in all of its testcases, escaping &lt;CODE&gt;C:\foo\bar\baz&lt;/CODE&gt; correctly,  it forgets that double-quote characters are equally problematic.  &lt;/P&gt;

&lt;P&gt;I can fix this fairly easily just by tracing through the code and since the set of testcases is pretty much already there,  and I'll get it fixed in the next release. &lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2013 18:01:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97739#M5387</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2013-07-17T18:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to escape double quotes in a Dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97740#M5388</link>
      <description>&lt;P&gt;Thanks Nick, let me know when this is available. I am really surprised that nobody asked about this in splunk so far. I feel its such a basic requirement.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2013 05:48:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97740#M5388</guid>
      <dc:creator>ma_anand1984</dc:creator>
      <dc:date>2013-07-18T05:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to escape double quotes in a Dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97741#M5389</link>
      <description>&lt;P&gt;For the sake of new splunkers,&lt;/P&gt;

&lt;P&gt;I'm using Core Splunk module SimpleResultsTable. But with the addition of SV (Side View utils), i can access special fields like $click.fields.msg$. they are called $foo$ tokens&lt;/P&gt;

&lt;P&gt;if you have SV installed go to &lt;BR /&gt;
http://&lt;SPLUNK&gt;/en-US/app/sideview_utils/custom_keys&lt;BR /&gt;
http://&lt;SPLUNK&gt;/en-US/app/sideview_utils/linking2_tables&lt;/SPLUNK&gt;&lt;/SPLUNK&gt;&lt;/P&gt;

&lt;P&gt;for more information&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:22:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-escape-double-quotes-in-a-Dashboard/m-p/97741#M5389</guid>
      <dc:creator>ma_anand1984</dc:creator>
      <dc:date>2020-09-28T14:22:41Z</dc:date>
    </item>
  </channel>
</rss>

