<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problem with field that contains character &amp;quot;\\&amp;quot; in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/problem-with-field-that-contains-character-quot-quot/m-p/63262#M15632</link>
    <description>&lt;P&gt;If it is exactly as you have described, it has to be a bug and I would open a Support Case with Splunk right away.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jun 2015 05:46:22 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-06-08T05:46:22Z</dc:date>
    <item>
      <title>problem with field that contains character "\\"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/problem-with-field-that-contains-character-quot-quot/m-p/63261#M15631</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a log with this type of content: &lt;CODE&gt;domain\\user&lt;/CODE&gt;. I have extracted this info with field extraction called &lt;CODE&gt;src_user&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;When I do a search with &lt;CODE&gt;src_user=* | table src_user&lt;/CODE&gt;, the response shows &lt;CODE&gt;domain\user&lt;/CODE&gt; instead of &lt;CODE&gt;domain\\user&lt;/CODE&gt;. One of the &lt;CODE&gt;\&lt;/CODE&gt; characters is stripped.&lt;/P&gt;

&lt;P&gt;Then when I am doing a &lt;CODE&gt;searchFieldsToDisplay&lt;/CODE&gt; to get &lt;CODE&gt;src_user&lt;/CODE&gt; value I get &lt;CODE&gt;domain\user&lt;/CODE&gt; and I can not set a new search with this searchField value.&lt;/P&gt;

&lt;P&gt;Does anyone know how to solve this?&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2012 16:41:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/problem-with-field-that-contains-character-quot-quot/m-p/63261#M15631</guid>
      <dc:creator>are0002</dc:creator>
      <dc:date>2012-02-02T16:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: problem with field that contains character "\\"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/problem-with-field-that-contains-character-quot-quot/m-p/63262#M15632</link>
      <description>&lt;P&gt;If it is exactly as you have described, it has to be a bug and I would open a Support Case with Splunk right away.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2015 05:46:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/problem-with-field-that-contains-character-quot-quot/m-p/63262#M15632</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-06-08T05:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: problem with field that contains character "\\"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/problem-with-field-that-contains-character-quot-quot/m-p/63263#M15633</link>
      <description>&lt;P&gt;trying to see your regular expression because you must be missing something, and  is the problem that must come. and also check if you have  not escape "\" s inside.&lt;BR /&gt;
without your expression regular and an example of data I do not guess more.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2015 08:08:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/problem-with-field-that-contains-character-quot-quot/m-p/63263#M15633</guid>
      <dc:creator>fdi01</dc:creator>
      <dc:date>2015-06-08T08:08:30Z</dc:date>
    </item>
  </channel>
</rss>

