Splunk Search
Highlighted

How to Use * in escape sequence?

Path Finder

We can use \ as an escape sequence for special characters ",",(,),[,] and so on. How to use for * character?

0 Karma
Highlighted

Re: How to Use * in escape sequence?

SplunkTrust
SplunkTrust

In what command do you want to escape the *?

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: How to Use * in escape sequence?

Communicator

If I understand your meaning, you are trying to find events that contain the asterisk (*) character. If so, then this is not possible using the backslash since Splunk treats the asterisk as a major breaker (see Event Segmentation below). According to the Search manual, if you want to search for an asterisk you will need to run a post-filtering regex search on the data, such as:

index=_internal | regex ".*\*.*"

References:
Event Segmentation - http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/Abouteventsegmentation
Search Manual (About Seach Language Syntax) - http://docs.splunk.com/Documentation/Splunk/6.2.1/Search/Aboutsearchlanguagesyntax

0 Karma
Highlighted

Re: How to Use * in escape sequence?

Path Finder

oh thanks badarsebard

0 Karma