Getting Data In

Replace single quotes with double quotes

daniel333
Builder

All,

We have a lot of key value pairs using single quotes. I am THINKING there is a way to fix this using SEDCMD. But honeslty I don't see how. Any ideas? I can do them as one offs pretty easy, but I'd rather just have one SEDCMD for it all.

myvariable='wedfwerfwe' would be myvariable="wedfwerfwe"

0 Karma

Grumpalot
Communicator

@daniel333 take a look at the following document

https://docs.splunk.com/Documentation/Splunk/6.6.2/Data/Anonymizedata

There may be a few ways you can address in a props.conf

if you are able to regex out where your KV pairs are coming from you can use that solution.

If not then the other option will be doing a complete replace of ' to " in that file source.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...