Splunk Search

How to concatenate a string with a value containing special characters?

snehal8
Path Finder

Hello Everyone,

I have a file containing Account ="xxx/\xxx/\xxx/\xx" value and this needs to be concatenated with a string, say "my account" .

when i tried following search:

index=myindex  | eval description= "my account" + Account | table description

getting blank for "description" .

Can any one guide me where aI'm going wrong ??? or this is because of the "/\" character in the string?

Thanks

0 Karma
1 Solution

snehal8
Path Finder

Hello All,

Thanks for your reply, the problem was Account string contain the two values with line break. so i used mvjoin command to remove line and now it is working perfectly fine.

Once again thanks all !!

View solution in original post

0 Karma

snehal8
Path Finder

Hello All,

Thanks for your reply, the problem was Account string contain the two values with line break. so i used mvjoin command to remove line and now it is working perfectly fine.

Once again thanks all !!

0 Karma

Runals
Motivator

Do the quote characters show up in the Account field? If so I wonder if that is throwing it off. Maybe try the following before your eval

... | rex field=Account "\"(?<Account>[^\"]+)" | ...
0 Karma

kendrickt
Path Finder

I don't think the characters will matter.

To prove this, try replacing them with something else?

index=myindex | eval rfield=REPLACE(Account, "/", "-") | eval description="my account" + rfield | table description
0 Karma

snehal8
Path Finder

Thanks for reply @kendrickt.. same not getting display !!!

0 Karma

mzorzi
Splunk Employee
Splunk Employee

use .

index=myindex | eval description= "my account".Account | table description

0 Karma

snehal8
Path Finder

Thanks for reply @mzorzi. but it is not working.

0 Karma

ramdaspr
Contributor

Can you paste what the output of the below code looks like?
I did a quick test of the code above and it seems to work fine

index=myindex | table Account

0 Karma

snehal8
Path Finder

Thanks for reply @ramdaspr. the problem was this string it contain line break, so it was not coming. i used "mvjoin" command for removing line. that it worked !!! 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! &#x1f308; In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...