I have an input that offers me x sources
index="xxxxx" sourcetype=xxxxx | dedup source | table source
The problem is when I open the panel in a search it shows me the source with a single \ and it needs two \ to give me the actual output
It seems I am close when using | rex mode=sed field=source "s/\\{1}/\\\//g" | dedup source | table source
The output is now:
source=D:\/xxxx\/xxxxx\/xxxx\/xxxxx\/xxxx\/xxxx.log
I tried to search and tried different options, but didn't found the correct rex 'line' that also changes the / into \ , in order to get the output:
source=D:\xxxx\xxxxx\xxxx\xxxxx\xxxx\xxxx.log
Hi,
Can you try the below code,
| eval source = replace(source,"\\\\","\\\\\\\\")
Sid
Excellent !
Welcome. Please accept is as answer when you get time. Have a nice day.