All Apps and Add-ons

Why is a field value which has double quotes getting truncated when writing the search?

Babuduraiswamy
Engager

The value from the CommandLine field getting truncated.

I am use index search.
index=* source="process" 
| table host CommandLine

The value is truncated in the table result field CommandLine

eg:
Input field
CommandLine= "-propertyfile=D:/projects/Testing/properties/perf "-Dtest_jvm_id=002 col 1" -Dbootstrap.folder=D:/projects/Testing/properties"

After search result:
CommandLine= "-propertyfile=D:/projects/Testing/properties/perf "

I need to remove the double quotes from the field like this "-propertyfile=D:/projects/Testing/properties/perf -Dtest_jvm_id=002 col 1-Dbootstrap.folder=D:/projects/Testing/properties"

 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It looks like CommandLine has been extracted normally although perhaps not as you had anticipated. Please share your raw event in a code block </> 

0 Karma

Babuduraiswamy
Engager

Here is the sample raw text from the commandLine.
<>CommandLine="C:\appserver/java/8.0/bin/java -xxx.install.area=C:\appserver /YYYYYYYYY/properties/perf "-Dxxx_jvm_id=xxx col 12" -DDDDDDD.folder=D:/xxxxxxxx "-Dcolumn_identifier=xxx col 12" C:\appserver\profiles\XXXXX\config XXX WYYYYNxxx01 YYYYYYYYY"</>

 

I just want to remove the double quotes from the field values. I tried using Replace function, it did not work.

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...