<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk query Help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-adding-pipe-quot-l-quot-for-all-results/m-p/611379#M212567</link>
    <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| table PeriodDate VendorName ContractName OccMetricCode Pagekey TransactionType TransactionDatetime ResponseTime(ms) Comment
| foreach * [ eval "&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;"="|".'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'."|"] &lt;/LI-CODE&gt;</description>
    <pubDate>Tue, 30 Aug 2022 21:18:27 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2022-08-30T21:18:27Z</dc:date>
    <item>
      <title>Help adding pipe "l" for all results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-adding-pipe-quot-l-quot-for-all-results/m-p/611366#M212563</link>
      <description>&lt;P&gt;Hello&amp;nbsp; - I am getting the below error. I am trying to add pipe "|"&amp;nbsp; for all the results.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Error : Failed to parse templatized search for field 'ResponseTime(ms)'&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;My search :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;| table PeriodDate VendorName ContractName OccMetricCode Pagekey TransactionType TransactionDatetime ResponseTime(ms) Comment&lt;BR /&gt;| foreach * [ eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;="|".&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;."|"]&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not getting pipe seperated results only for ResponseTime&lt;/P&gt;
&lt;TABLE border="1" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;PeriodDate&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;ResponseTime(ms)&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;Comment&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;|2022/08/30|&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;0&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;||&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 22:52:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-adding-pipe-quot-l-quot-for-all-results/m-p/611366#M212563</guid>
      <dc:creator>kc_prane</dc:creator>
      <dc:date>2022-08-30T22:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query Help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-adding-pipe-quot-l-quot-for-all-results/m-p/611379#M212567</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| table PeriodDate VendorName ContractName OccMetricCode Pagekey TransactionType TransactionDatetime ResponseTime(ms) Comment
| foreach * [ eval "&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;"="|".'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'."|"] &lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 30 Aug 2022 21:18:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-adding-pipe-quot-l-quot-for-all-results/m-p/611379#M212567</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-08-30T21:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Help adding pipe "l" for all results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-adding-pipe-quot-l-quot-for-all-results/m-p/611389#M212572</link>
      <description>&lt;P&gt;To add to&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;reply. When handling field names that start with numbers, or contain 'odd' characters, e. g. in this case the brackets, (), you need to use single quote characters on the right hand side of eval. It's always sensible, particularly when using foreach, to DOUBLE quote the left hand side of the eval, i.e.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval "QUOTED NAME"='Quoted(ms) field'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 23:23:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-adding-pipe-quot-l-quot-for-all-results/m-p/611389#M212572</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-08-30T23:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query Help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-adding-pipe-quot-l-quot-for-all-results/m-p/614003#M213371</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 22:41:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-adding-pipe-quot-l-quot-for-all-results/m-p/614003#M213371</guid>
      <dc:creator>kc_prane</dc:creator>
      <dc:date>2022-09-21T22:41:17Z</dc:date>
    </item>
  </channel>
</rss>

