Splunk Search

Why do I receive "Error in 'eval' command: The expression is malformed. An unexpected character is reached at '”%Y-%m-%d %H:%M”)'." in my Splunk Light search?

tomasnelson
Explorer

Hi everyone !
I am a new user in Splunk (Great application and these days very useful); I read this document and I tried to reproduce the search but in my Splunk Free it does not work, reporting this error: Error in 'eval' command: The expression is malformed. An unexpected character is reached at '”%Y-%m-%d %H:%M”)'.

There is some limitation with my version? or the article is have something wrong ? I can not identify the solution...
please help...!!!!

https://www.splunk.com/blog/2016/08/12/detecting-early-signs-of-compromise-using-windows-sysinternal...

0 Karma
1 Solution

woodcock
Esteemed Legend

You have the @!#$%^&* Microsoft Windows left-and-right double-quotes ( and )instead of the correct ambiguous one ( " ).

View solution in original post

0 Karma

woodcock
Esteemed Legend

You have the @!#$%^&* Microsoft Windows left-and-right double-quotes ( and )instead of the correct ambiguous one ( " ).

0 Karma

tomasnelson
Explorer

Thanks a lot..... woodcock 😃
finally i see the error with your comment. ;=)

0 Karma

tomasnelson
Explorer

I think I expressed myself wrong, I leave a more explicit picture about the error:alt text

0 Karma

woodcock
Esteemed Legend

You probably forgot the comma between the field namd and the time expression. So you have something like eval foo=strfime(bar "%Y-%m-%d %H:%M") instead of eval foo=strfime(bar, "%Y-%m-%d %H:%M").

0 Karma

adonio
Ultra Champion

hello tomasnelson,
remove the singe quotes ' ' all you need is this: eval blah = srftime(_time, ”%Y-%m-%d %H:%M”)

0 Karma

adonio
Ultra Champion

hello tomasnelson,
remove the singe quotes ' ' all you need is this: eval blah = srftime(_time, ”%Y-%m-%d %H:%M”)

0 Karma
Get Updates on the Splunk Community!

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...

What's New in Splunk Cloud Platform 9.2.2406?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2406 with many ...

Enterprise Security Content Update (ESCU) | New Releases

In August, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...