Splunk Search

Using a literal pipe "|" character in an extracted regex field

jbrenner
Path Finder

I'm creating an extracted field using a regex, and I want to use a literal pipe "|" character in the regex.
My understanding is to use a backspace as an escape character as follows:

\|

When I save the regex and return to it, however, the backslash has been removed.
What am I doing wrong?

Thanks,
Jonathan

Tags (1)
0 Karma

jbrenner
Path Finder

Hi,

I don't know what I was doing wrong, but after trying some different things, it stopped stripping out the escape characters.
I think I must have doing something wrong in the UI.
To answer your question, though, I was selecting the dropdown that says "Event Actions" and selecting "Extract Fields"

Thanks for responding,
Jonathan

0 Karma

somesoni2
Revered Legend

Glad your issue is resolved. If there are no other followup (related) questions, they you can close this question by accepting this as an answer.

0 Karma

jbrenner
Path Finder

Sorry. meant to say "backslash," not "backspace" 🙂

0 Karma

somesoni2
Revered Legend

What's the full regex that you're using? How are you saving it, using IFX (interactive field extraction wizard) OR directory through settings?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...