Reporting

Splunk doesn't delimit my fields if Field data ends in a '\' (backslash)

poojamistry
Engager

My data is delimited by say Pipe (|), and some fields of the data end in a backslash, and the delimiter seems to be escaped. I have control on what delimits the data, but not how the data ends in. Is there a work around for this?

Tags (1)

markthompson
Builder

Take a look at the split command,
alt text
Then you would have to use mvindex

Think I might have misinterpreted the question, if the above is what you're looking for, great.
If not, I'd suggest you use a regex to split the fields, I can provide more help if you confirm which is the answer you're looking for

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...