Splunk Search

Using a literal pipe "|" character in an extracted regex field

jbrenner
Path Finder

I'm creating an extracted field using a regex, and I want to use a literal pipe "|" character in the regex.
My understanding is to use a backspace as an escape character as follows:

\|

When I save the regex and return to it, however, the backslash has been removed.
What am I doing wrong?

Thanks,
Jonathan

Tags (1)
0 Karma

jbrenner
Path Finder

Hi,

I don't know what I was doing wrong, but after trying some different things, it stopped stripping out the escape characters.
I think I must have doing something wrong in the UI.
To answer your question, though, I was selecting the dropdown that says "Event Actions" and selecting "Extract Fields"

Thanks for responding,
Jonathan

0 Karma

somesoni2
Revered Legend

Glad your issue is resolved. If there are no other followup (related) questions, they you can close this question by accepting this as an answer.

0 Karma

jbrenner
Path Finder

Sorry. meant to say "backslash," not "backspace" 🙂

0 Karma

somesoni2
Revered Legend

What's the full regex that you're using? How are you saving it, using IFX (interactive field extraction wizard) OR directory through settings?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...