Reporting

Splunk doesn't delimit my fields if Field data ends in a '\' (backslash)

poojamistry
Engager

My data is delimited by say Pipe (|), and some fields of the data end in a backslash, and the delimiter seems to be escaped. I have control on what delimits the data, but not how the data ends in. Is there a work around for this?

Tags (1)

markthompson
Builder

Take a look at the split command,
alt text
Then you would have to use mvindex

Think I might have misinterpreted the question, if the above is what you're looking for, great.
If not, I'd suggest you use a regex to split the fields, I can provide more help if you confirm which is the answer you're looking for

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...