All Apps and Add-ons

How to use CDATA in a search where the value contains an equals sign

kragel
Path Finder

I have a variable with an equals sign in it and I want to search on it. The equals sign seems to mess up the search. If I paste it in a CDATA string it doesn't seem to read the string either. If I manually put quotes around the actual value and use Search it works fine.

<module name="Search">
  <param name="search">$row.fields.pp_msgid$</param>
</modlue>

row.fields.pp_msgid=CAELFq+=4VHzpb97vrxLCwY2bqe5MM-P7BHMuCgz9CQ3zcQz_Pg@subdomain.domain.com

I tried the following but was unsuccessful.

<module name="Search">
  <param name="search"><![CDATA[$row.fields.pp_msgid$]]></param>
</module>

Can anyone suggest a way to search on the entire string? Or if I'm missing something with my CDATA line, can you help me out? Thanks.

0 Karma
1 Solution

sideview
SplunkTrust
SplunkTrust

I'm pretty sure you just want

<module name="Search">
  <param name="search">"$row.fields.pp_msgid$"</param>
</module>

You don't need to mess around with CDATA - that's actually for xml-unsafe characters in the param string, not for characters in the evaluated $foo$ token.

View solution in original post

sideview
SplunkTrust
SplunkTrust

I'm pretty sure you just want

<module name="Search">
  <param name="search">"$row.fields.pp_msgid$"</param>
</module>

You don't need to mess around with CDATA - that's actually for xml-unsafe characters in the param string, not for characters in the evaluated $foo$ token.

kragel
Path Finder

Thanks!!!! That worked.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...