Splunk Search

Right to left text in a left to right expression causing cursor and keyboard layout issues

landster
Explorer

I am trying to write an eval expression to translate a few different languages into English.   One of the languages is Hebrew which is a right to left language, and when I use the Hebrew text in my query, my cursor location is no longer predictable, and I cannot copy/paste the Hebrew into an otherwise left to right query expression.  I then tried to create a macro to do the evaluation, but I ran into the same issue.  Even using a different browser(Firefox vs. Brave), or a different program (notepad++), but I always encounter the cursor/keyboard anomalies after pasting the text into my query.   I need to translate a few different strings within a case eval expression. 

Is anyone aware of any similar issues being encountered and/or of any potential work arounds? 
Does someone have an alternate suggestion as to how I can accomplish the translations?

Here is an example of what I am trying to do:

| eval appName = case(appName="플레이어","player",appName="티빙","Tving",appName=...

This Hebrew text is an example of where I run into issues:

כאן ארכיון

0 Karma
1 Solution

landster
Explorer

I am using Splunk Enterprise 9.2.1. on CentOS Linux kernel 3.10.0-1160.119.1.el7.x86_64 and my desktop OS is Windows 10 Enterprise.  I do not switch to RTL as I exclusively use LTR.  In this case, the RTL characters are included as titles in some data.

I got it to work by creating a macro for the eval function, and only pasting in the RTL text as the very last step before saving it.   Then I just added the macro to my search query so I did not need to include any of the RTL encoded characters in the search itself explicitly.

 

View solution in original post

0 Karma

jewnix-splunk
Splunk Employee
Splunk Employee

What version of Splunk are you using?

What OS are you using on your desktop?

What do you use to switch the the input fro LTR to RTL?

landster
Explorer

I am using Splunk Enterprise 9.2.1. on CentOS Linux kernel 3.10.0-1160.119.1.el7.x86_64 and my desktop OS is Windows 10 Enterprise.  I do not switch to RTL as I exclusively use LTR.  In this case, the RTL characters are included as titles in some data.

I got it to work by creating a macro for the eval function, and only pasting in the RTL text as the very last step before saving it.   Then I just added the macro to my search query so I did not need to include any of the RTL encoded characters in the search itself explicitly.

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...