Splunk Search

What is the correct syntax to extract data between two strings in a search within a form?

RVDowning
Contributor

I can't seem to find any correct syntax to extract data between two strings when attempting to do it in a search string within a form. There must be some special syntax. Is mode=sed required for some reason?

Tags (5)
0 Karma

RVDowning
Contributor

Ok, worked it out. Seems I had forgotten the semicolon in the < and &gt:

0 Karma
Get Updates on the Splunk Community!

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

What's New in Splunk Observability - July 2025

What’s New?  We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what ...