Getting Data In

What's the best way to escape characters in a drilldown if a field value has quotes?

HeinzWaescher
Motivator

Hi,

some of my values have quotes in the string. Using the fieldlist for filtering, Splunk is automatically escaping these characters in the base search.

fieldA=this is a "test" value ---> fieldA="this is a \"test\" value"

When I try to use fieldA as token drilldown, it does not work for values with quotes because these characters are not automatically escaped. What it the best way to handle this situation?

My first approach would be to use:

| eval fieldA=replace(fieldA,"\"","")
| search fieldA="this is a test value"

Is there a better one or a more automized one?

1 Solution

niketn
Legend

@HeinzWaescher, double quotes need to be escaped within string. So, you can try setting the token like the following through eval instead of set:

    <drilldown>
      <eval token="cluster_message_token">replace($row.message$,"\"","\\\"")</eval>
    </drilldown>
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

niketn
Legend

@HeinzWaescher, double quotes need to be escaped within string. So, you can try setting the token like the following through eval instead of set:

    <drilldown>
      <eval token="cluster_message_token">replace($row.message$,"\"","\\\"")</eval>
    </drilldown>
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

HeinzWaescher
Motivator

thanks, this works fine and is easier to handle than the workaround mentioned above 🙂

0 Karma

niketn
Legend

Cheers... glad this worked 🙂

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

rjthibod
Champion

Can you share more of your code? The answer probably depends on how you are using the tokens and the various token syntax options. So, seeing your code would be helpful.

0 Karma

HeinzWaescher
Motivator

The token for fieldA is set this way:

    <drilldown>
      <condition>
        <set token="cluster_message_token">$row.message$</set>
      </condition>
    </drilldown>

In a second panel it used as a filter in a later search:

base search and pipes...
| search cluster_message="$cluster_message_token$"

It is set as fieldA="this is a "test" value", so not working correctly.
I fixed it with the workaround mentioned above, but am wondering why escaping is not handled automatically here.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...