Splunk Enterprise

Regarding rex in SPL2 supports raw string literals.

inventsekar
SplunkTrust
SplunkTrust

Dear Splunk Gurus, 
Pls find these lines in the given page below:
Differences between SPL and SPL2
The differences between the SPL and SPL2 rex command are described in these sections.

Support for raw string literals

SPL2 supports raw string literals.

https://help.splunk.com/en/splunk-cloud-platform/search/spl2-search-reference/rex-command/rex-comman...

(removed the extended example in this table below)

Version Example

SPL...rex "From: (?<from>.*) To: (?<to>.*)" field=myfield
SPL2...rex field=myfield "From: (?<from>.*) To: (?<to>.*)"


Could you pls give me an example, with the "raw string literals" sample log line, so that, learners can understand it easily.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The best way to get clarification on a Documentation page is to submit feedback on the page.  Click the "Share feedback" button at the bottom of the page.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...