Splunk Enterprise

Why is Colon Character in JS not working?

rkeq0515
Path Finder

I am trying to use a colon ( : ) in my js file; however, I do not see results when I use the colon.  I verified that the command works with the colon when I run it within a Search window.   I also have it working without the colon in the js file.  I just can't seem to use the colon in the js file. 

The following code in my js file does not work.

 

... | search (path IN (\"*:\\windows\\*\")) | stats count

 

 

The following code in my js file works.

 

... | search (path IN (\"*\\windows\\*\")) | stats count

 

 

I tried to escape it like I did the double-quotes, but that did not work.  Is there a way to use the colon in the js file?

 

Thanks 

0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@rkeq0515 - I always try multiple try-and-error when dealing with \ (backward slash).

One of these should work:

... | search path IN (\"*:\\windows\\*\") | stats count
... | search path IN (\"*:\\\windows\\\*\") | stats count
... | search path IN (\"*:\\\\windows\\\\*\") | stats count

(3 or 4 slashes should work)

 

I hope this helps!!!

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@rkeq0515 - I always try multiple try-and-error when dealing with \ (backward slash).

One of these should work:

... | search path IN (\"*:\\windows\\*\") | stats count
... | search path IN (\"*:\\\windows\\\*\") | stats count
... | search path IN (\"*:\\\\windows\\\\*\") | stats count

(3 or 4 slashes should work)

 

I hope this helps!!!

0 Karma

rkeq0515
Path Finder

Thank you!  The 4 back slashes worked.  I was focused on the colon since 2 back slashes were working.  However, I see that it wasn't providing the correct data.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...