Splunk Search

Help fixing string with newline that is not searchable

sjova
Engager

Hi,

if my string is "asdf .\r\n asdf" and I filter on that (Add to search) I get "No results found".

Any idea how to fix this?

Thanks,
Gunnar

0 Karma
1 Solution

manjunathmeti
Champion

Try this:

index=INDEXNAME FIELDNAME="asdf*asdf"

View solution in original post

sjova
Engager

Thanks, I just replaced \r\n with \n and then it worked fine 🙂

0 Karma

manjunathmeti
Champion

Try this:

index=INDEXNAME FIELDNAME="asdf*asdf"

sjova
Engager

It is not possible to add it more globally to it affects all my queries(that have line breaks in them)?

0 Karma

manjunathmeti
Champion

It's problem with \r. Use * in place of \r. All other characters will match.

index=INDEXNAME FIELDNAME="asdf *\n asdf"
0 Karma

sjova
Engager

asdf is just an example. That string is really a stacktrace from a program. Any idea how I can do this in a general way (so that my queries work)?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...