<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search for splunk event which has greater than symbol in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-for-splunk-event-which-has-greater-than-symbol/m-p/625211#M217336</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a Splunk event "Application -&amp;gt; start of the log".&lt;/P&gt;&lt;P&gt;When I try to search for this log using the exact text then I do not get any results.&lt;/P&gt;&lt;P&gt;I see that the greater than symbol is causing the problem. When I split my search command as "Application -" AND "start of the log" then splunk was able to find the event.&lt;/P&gt;&lt;P&gt;So how do I escape the greater than symbol in splunk search command? I tried &amp;amp;gt; which didn't work.&lt;/P&gt;&lt;P&gt;(I also want to use this search text in "transaction startswith=" command so I cannot use `AND` condition)&lt;/P&gt;</description>
    <pubDate>Sun, 25 Dec 2022 07:29:53 GMT</pubDate>
    <dc:creator>sasank</dc:creator>
    <dc:date>2022-12-25T07:29:53Z</dc:date>
    <item>
      <title>Search for splunk event which has greater than symbol</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-for-splunk-event-which-has-greater-than-symbol/m-p/625211#M217336</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a Splunk event "Application -&amp;gt; start of the log".&lt;/P&gt;&lt;P&gt;When I try to search for this log using the exact text then I do not get any results.&lt;/P&gt;&lt;P&gt;I see that the greater than symbol is causing the problem. When I split my search command as "Application -" AND "start of the log" then splunk was able to find the event.&lt;/P&gt;&lt;P&gt;So how do I escape the greater than symbol in splunk search command? I tried &amp;amp;gt; which didn't work.&lt;/P&gt;&lt;P&gt;(I also want to use this search text in "transaction startswith=" command so I cannot use `AND` condition)&lt;/P&gt;</description>
      <pubDate>Sun, 25 Dec 2022 07:29:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-for-splunk-event-which-has-greater-than-symbol/m-p/625211#M217336</guid>
      <dc:creator>sasank</dc:creator>
      <dc:date>2022-12-25T07:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: Search for splunk event which has greater than symbol</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-for-splunk-event-which-has-greater-than-symbol/m-p/625217#M217339</link>
      <description>&lt;P&gt;I have no problems searching for the '&amp;gt;' character.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="richgalloway_0-1671918775323.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23139iF9573B8FE0A9595C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="richgalloway_0-1671918775323.png" alt="richgalloway_0-1671918775323.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please share your exact SPL and a sample event so we have a better view of the problem.&amp;nbsp; What version of Splunk are you using?&lt;/P&gt;</description>
      <pubDate>Sat, 24 Dec 2022 21:55:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-for-splunk-event-which-has-greater-than-symbol/m-p/625217#M217339</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-12-24T21:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Search for splunk event which has greater than symbol</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-for-splunk-event-which-has-greater-than-symbol/m-p/625223#M217344</link>
      <description>&lt;P&gt;Hi, I saw the RAW event and found that the text in the event is "Application -\u003e start of the log"&lt;/P&gt;&lt;P&gt;The greater than symbol is in unicode.&lt;/P&gt;&lt;P&gt;So I have to search as "&lt;SPAN&gt;Application&lt;/SPAN&gt;&amp;nbsp;-\\u003e&amp;nbsp;&lt;SPAN&gt;start of the log&lt;/SPAN&gt;".&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Dec 2022 08:05:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-for-splunk-event-which-has-greater-than-symbol/m-p/625223#M217344</guid>
      <dc:creator>sasank</dc:creator>
      <dc:date>2022-12-25T08:05:50Z</dc:date>
    </item>
  </channel>
</rss>

