Splunk Search

How to query a field in DBXQuery that contains colon?

LearningGuy
Motivator

Hello,
How to query a field in DBXQuery that contains colon?  
I ran the following query and got an error.  Thank you 
| dbxquery connection=visibility query="select abc:def from tableCompany"
org.postgresql.util.PSQLException: ERROR: syntax error at or near ":" Position:

I tried to put single quote
| dbxquery connection=visibility query="select 'abc:def' from tableCompany"
but it gave me the following result

?column?
abc:def
abc:def



Labels (2)
Tags (1)
0 Karma
1 Solution

etoombs
Path Finder

My bad. I didn't look to see what database you were using. You may need quotes around it = "abc:def". Since you're doing this inside a quoted string, you may need to escape them as \" in the string. 

View solution in original post

etoombs
Path Finder

My bad. I didn't look to see what database you were using. You may need quotes around it = "abc:def". Since you're doing this inside a quoted string, you may need to escape them as \" in the string. 

LearningGuy
Motivator


Your suggestion worked. Thank you so much
| dbxquery connection=visibility query="select \"abc:def\" from tableCompany"

0 Karma

etoombs
Path Finder

Try brackets around the field name - [abc:def]

LearningGuy
Motivator

Hello,
I put brackets around the field name [abc:def], but it still didn't work and got the following error
org.postgresql.util.PSQLException: ERROR: syntax error at or near "["

Thank you

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...