- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

pavanae
Builder
02-08-2023
11:10 AM
I have a Splunk query as below which pulls some events.
index="windows_events" TargetFileName="*startup*"
Now from the events I picked the below TargetFileName field value
\Device\HarddiskVolume3\Users\XYZ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to AbC.lnk
Now I wanted to search specifically for the above field and for that I used the below query which gives me no results.
`get_All_CrowdstrikeEDR` event_simpleName=FileCreateInfo os="Win" TargetFileName="*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*"
Now, what I dont understand is when I tried the first query I am able to see some events though I used wild cards before and after startup
Now, when I extended the wild card with actual value why isn't working?
Can't I use backslashes in Splunk searches?
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
02-08-2023
11:23 AM
Have you tried escaping the backslashes? The \ character is used for escaping so to specify a \ you must escape it.
`get_All_CrowdstrikeEDR` event_simpleName=FileCreateInfo os="Win" TargetFileName="*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*"
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
02-08-2023
11:23 AM
Have you tried escaping the backslashes? The \ character is used for escaping so to specify a \ you must escape it.
`get_All_CrowdstrikeEDR` event_simpleName=FileCreateInfo os="Win" TargetFileName="*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*"
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
