Reporting

Splunk doesn't delimit my fields if Field data ends in a '\' (backslash)

poojamistry
Engager

My data is delimited by say Pipe (|), and some fields of the data end in a backslash, and the delimiter seems to be escaped. I have control on what delimits the data, but not how the data ends in. Is there a work around for this?

Tags (1)

markthompson
Builder

Take a look at the split command,
alt text
Then you would have to use mvindex

Think I might have misinterpreted the question, if the above is what you're looking for, great.
If not, I'd suggest you use a regex to split the fields, I can provide more help if you confirm which is the answer you're looking for

0 Karma
Get Updates on the Splunk Community!

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...

What’s New in Splunk Cloud Platform 9.1.2308?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2308! Analysts can ...