Splunk Search

Help fixing string with newline that is not searchable

Engager

Hi,

if my string is "asdf .\r\n asdf" and I filter on that (Add to search) I get "No results found".

Any idea how to fix this?

Thanks,
Gunnar

0 Karma
1 Solution

Influencer

Try this:

index=INDEXNAME FIELDNAME="asdf*asdf"

View solution in original post

Engager

Thanks, I just replaced \r\n with \n and then it worked fine 🙂

0 Karma

Influencer

Try this:

index=INDEXNAME FIELDNAME="asdf*asdf"

View solution in original post

Engager

It is not possible to add it more globally to it affects all my queries(that have line breaks in them)?

0 Karma

Influencer

It's problem with \r. Use * in place of \r. All other characters will match.

index=INDEXNAME FIELDNAME="asdf *\n asdf"
0 Karma

Engager

asdf is just an example. That string is really a stacktrace from a program. Any idea how I can do this in a general way (so that my queries work)?

0 Karma