Splunk Search

Add comments to search code inside search field

sergeblr
Explorer

Hello everybody, using Splunk 8.1.0 and relaterd to https://docs.splunk.com/Documentation/Splunk/8.1.0/Search/Parsingsearches trying to add comments via ```my_comment``` to search request, but there is error.

Only `comment("my_comment")` works, but it is not what i need...

How to add comment to search request like /* my_comment */ or // my_comment ?

Labels (1)

inventsekar
SplunkTrust
SplunkTrust

Hi @sergeblr may we know your full search query(after hiding hostname, important field-values) and Splunk version please

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

sergeblr
Explorer

Hi, @inventsekar 

index=apps
host=host*
CASE(ERROR) AND "com.*"
```some comment here```

inventsekar
SplunkTrust
SplunkTrust
index=apps host=host* ERROR  ```some comment here```

are you able to do this search, please check.

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

sergeblr
Explorer

Безымянный.pngReturns

 

Error in 'SearchParser': You must provide a macro expression.

 

Splunk 8.0.1

inventsekar
SplunkTrust
SplunkTrust

please try this... (this works fine for me)

 

index=_internal CASE(ERROR) /*test*/

 

PS  - karma points appreciated, if this solves your question, please accept it as the solution. thanks.

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

sergeblr
Explorer

For this query /*test*/ parsed as:

'/' symbol, THEN any text (*), THEN 'test' word, THEN again any text (*) and '/' symbol, so this is not parsed as comment :((

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...