Getting Data In

Use of double qoutes in rex command arguments fails alerts in windows environment.

xli_splunk
Splunk Employee
Splunk Employee

Set up an alert with the search command:
source="C:\test\data\log1.txt" | rex v="(?.*)" | head 10
the alert has never been triggered, although the same search on Aplunk UI generates results.

0 Karma

ibob0304
Communicator

You should have tried by black slash \"(?.*)\"

0 Karma

xli_splunk
Splunk Employee
Splunk Employee

So don't use double quotes with rax command in scheduled searches for alerts. Just use a search like:
source="C:\test\data\log1.txt" | rex v=(?.*) | head 10
This works fine for alerts and is more readable.

ibob0304
Communicator
  " works fine on windows.
0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...