Getting Data In

Splunk Search with PIPE

cj
New Member

So I have an application in centos that monitors process creation and sends it to a remote syslog server which is also running the Universal Forwarder. The syslog is then forwarded to Splunk and I split it using the pipe "|" delimiter. However, I found that many applications like awk and sed use "|" to filter which also messes up the field separation in splunk. Does anyone know how to work around this?

This is when I'm in search.

 

 

Thanks

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Depends on the context, but you may need to escape the pipe with a backslash \|

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...