Splunk Enterprise

Escape quote in standard input?

Engager

Hello. I have a input script in python that gets data from db and puts them in stdin in the form field = "value". One field contains a json so I tried to escape quotes:
field = "{\"id\": \"a\"}"
but what I get in the field is "{\" losing the rest.
There is a way to escape quote in this case?
Thanks

Labels (1)
Tags (2)
0 Karma
1 Solution

Engager

Yes I did but is was non working until I found out to use autoescaped instead of auto as KVMODE.
Now it's working fine.
Thanks

View solution in original post

0 Karma

Engager

Yes I did but is was non working until I found out to use autoescaped instead of auto as KVMODE.
Now it's working fine.
Thanks

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

If your problem is resolved, please accept the answer to help future readers.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

SplunkTrust
SplunkTrust

Have you tried field = '{\"id\": \"a\"}'?

---
If this reply helps you, an upvote would be appreciated.
0 Karma