I created a dropdown Input for my dashboard and my token's name is "TEST\admin".On the search, Splunk doesn't understand the token's value, following an example:
source=dbx actionidname = "$token$"
source=dbx actionidname = "TEST\admin" - DOESN'T WORK
source=dbx actionidname = "TEST\admin" - IT'S WORK
How Can I include one slash in the middle of the token's value? Like this "TEST\admin".
Try something like this
source=dbx action_id_name = [| gentimes start=-1 | eval search=replace("$token$","\\\\","\\\\\\\\") | table search]
View solution in original post
It worked perfectly!