Splunk Search

Using a literal pipe "|" character in an extracted regex field

jbrenner
Path Finder

I'm creating an extracted field using a regex, and I want to use a literal pipe "|" character in the regex.
My understanding is to use a backspace as an escape character as follows:

\|

When I save the regex and return to it, however, the backslash has been removed.
What am I doing wrong?

Thanks,
Jonathan

Tags (1)
0 Karma

jbrenner
Path Finder

Hi,

I don't know what I was doing wrong, but after trying some different things, it stopped stripping out the escape characters.
I think I must have doing something wrong in the UI.
To answer your question, though, I was selecting the dropdown that says "Event Actions" and selecting "Extract Fields"

Thanks for responding,
Jonathan

0 Karma

somesoni2
Revered Legend

Glad your issue is resolved. If there are no other followup (related) questions, they you can close this question by accepting this as an answer.

0 Karma

jbrenner
Path Finder

Sorry. meant to say "backslash," not "backspace" 🙂

0 Karma

somesoni2
Revered Legend

What's the full regex that you're using? How are you saving it, using IFX (interactive field extraction wizard) OR directory through settings?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...