Splunk Search

How to use erex in a CLI search

jphilput1
Explorer

I'm running into an issue with the syntax for a CLI search using erex.

The problem seems to be with the double quotes. I've tried single quoting the erex examples and counter examples, but none of it seems effective.

This search works in the GUI:

index=name searchterm NOT otherterm |erex message examples="/foo/bar,/foobar" counterexamples="barfoo, foobar" |table item1,item2,item3,item4,item5 |uniq |sort item3

In the CLI, I've tried it a couple of different ways, and the closest I've gotten to a working search is:

index=name searchterm NOT otherterm |erex message examples='/foo/bar,/foobar' counterexamples='barfoo, foobar' |table item1,item2,item3,item4,item5 |uniq |sort item3

the CLI search results in "INFO: No matching fields exist"

Do any of you know what I'm doing wrong here?

Thanks!

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

What is the CLI command you're using?

Should be like this:

./splunk search 'index=name searchterm NOT otherterm |erex message examples="/foo/bar,/foobar" counterexamples="barfoo, foobar" |table item1,item2,item3,item4,item5 |uniq |sort item3'

View solution in original post

jkat54
SplunkTrust
SplunkTrust

What is the CLI command you're using?

Should be like this:

./splunk search 'index=name searchterm NOT otherterm |erex message examples="/foo/bar,/foobar" counterexamples="barfoo, foobar" |table item1,item2,item3,item4,item5 |uniq |sort item3'

jphilput1
Explorer

Thanks jkat54! That worked perfectly. Sorry for the delayed reply, work got in the way of work.

0 Karma

jkat54
SplunkTrust
SplunkTrust

No problem at all, thanks for coming back! @jphilput1

0 Karma

gabriel_vasseur
Contributor

I have never used the CLI, but I'm guessing from your description that it involves putting your SPL search string inside quotes and that the " inside your search are interfering with that? If that's the case, have you tried escaping all " with a backslash?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...