Dashboards & Visualizations

help me with dashboard XML

sravankaripe
Communicator

i am finding difficulty with dashboard XML beacause of

tag SubErrorCode
please help me with this

  <search>
   <query>-------------| rex "\"subErrorCode\":\"(?<SubErrorCode>w\w\w_\d+)"| dedup  SubErrorCode |table SubErrorCode </query>
  </search>
0 Karma
1 Solution

sravankaripe
Communicator

i got it by using escape characters

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@sravankaripe: Did your answer provide a working solution to your question? If yes, don't forget to click "Accept".

0 Karma

sravankaripe
Communicator

Ok, it's working for me

0 Karma

sravankaripe
Communicator

-------------| rex "\"subErrorCode\":\"(?<SubErrorCode&gtw\w\w_\d+)"| dedup SubErrorCode |table SubErrorCode

0 Karma

sravankaripe
Communicator

tag SubErrorCode

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...