Splunk Search

Using a literal pipe "|" character in an extracted regex field

jbrenner
Path Finder

I'm creating an extracted field using a regex, and I want to use a literal pipe "|" character in the regex.
My understanding is to use a backspace as an escape character as follows:

\|

When I save the regex and return to it, however, the backslash has been removed.
What am I doing wrong?

Thanks,
Jonathan

Tags (1)
0 Karma

jbrenner
Path Finder

Hi,

I don't know what I was doing wrong, but after trying some different things, it stopped stripping out the escape characters.
I think I must have doing something wrong in the UI.
To answer your question, though, I was selecting the dropdown that says "Event Actions" and selecting "Extract Fields"

Thanks for responding,
Jonathan

0 Karma

somesoni2
Revered Legend

Glad your issue is resolved. If there are no other followup (related) questions, they you can close this question by accepting this as an answer.

0 Karma

jbrenner
Path Finder

Sorry. meant to say "backslash," not "backspace" 🙂

0 Karma

somesoni2
Revered Legend

What's the full regex that you're using? How are you saving it, using IFX (interactive field extraction wizard) OR directory through settings?

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...