Splunk Search

How to search with result string with "../"?

mclane41
Explorer

Try this request on Splunk :

 

 

| makeresults | eval redir="../../app"

 

 

My request is automatically transformed by 

 

 

| makeresults | eval redir="app"

 

 

How can I have a work around ?

I try on chrome or firefox without success.

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @mclane41,

I tested your issue on an 8.2 version and the issue is present.

This means that this is a known issue solved with the new versions, so the only solution is to upgrade Splunk.

Ciao.

Giuseppe

 

View solution in original post

mclane41
Explorer

I work with the version Enterprise 8.2.0

mclane41_0-1677145819805.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mclane41,

I tested your issue on an 8.2 version and the issue is present.

This means that this is a known issue solved with the new versions, so the only solution is to upgrade Splunk.

Ciao.

Giuseppe

 

gcusello
SplunkTrust
SplunkTrust

Hi @mclane41,

also on 9.0.4 works fine!

gcusello_0-1677137884464.png

ciao.

Giuseppe

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Which version of Splunk are you using?  The first query works for me in 9.0.0.1.

richgalloway_0-1677089502677.png

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...