Splunk Search

How to concatenate strings with unicode character?

junlozhang
Explorer

I want to concatenate strings with special characters like "\t" and Unicode char "\u0006"

I tried

 

 

| makeresults 
| eval str="a"."\t"."b"

 

 

And got

 

 

a\tb

 

 

But what I want is

 

 

a  b

 

 

 

Also, I tried

 

 

| makeresults 
| eval str="a"."\u0006"."b"

 

 

And got

 

 

a\u0006b

 

 

 

What should I do?

Labels (1)
Tags (1)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@junlozhang 

 

Can you please share your use case where and how you want to use?  Just for trial I draft search in sublime using tab key and executed.  If you have specific use case then please share. 

 

| makeresults 
| eval str="a"."	"."b"

 

Screenshot 2021-05-08 at 3.37.00 PM.png

 

Screenshot 2021-05-08 at 3.37.12 PM.png

 

0 Karma

junlozhang
Explorer

@kamlesh_vaghela 

Thanks for the solution about "\t". And what about Unicode character? Does it mean there is no way to concatenate a Unicode character and a string?

Well, the reason I want to do this is that our log system has just switched to Splunk recently, and in order to make as least change as possible to the code of current downstream service, I'm trying to make the data fetched from Splunk has the same schema as the old log system (some fields in Splunk used to be separated by special character "\t" or Unicode character "\u0006")

 

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...