Splunk Search

Why do I receive "Error in 'eval' command: The expression is malformed. An unexpected character is reached at '”%Y-%m-%d %H:%M”)'." in my Splunk Light search?

tomasnelson
Explorer

Hi everyone !
I am a new user in Splunk (Great application and these days very useful); I read this document and I tried to reproduce the search but in my Splunk Free it does not work, reporting this error: Error in 'eval' command: The expression is malformed. An unexpected character is reached at '”%Y-%m-%d %H:%M”)'.

There is some limitation with my version? or the article is have something wrong ? I can not identify the solution...
please help...!!!!

https://www.splunk.com/blog/2016/08/12/detecting-early-signs-of-compromise-using-windows-sysinternal...

0 Karma
1 Solution

woodcock
Esteemed Legend

You have the @!#$%^&* Microsoft Windows left-and-right double-quotes ( and )instead of the correct ambiguous one ( " ).

View solution in original post

0 Karma

woodcock
Esteemed Legend

You have the @!#$%^&* Microsoft Windows left-and-right double-quotes ( and )instead of the correct ambiguous one ( " ).

0 Karma

tomasnelson
Explorer

Thanks a lot..... woodcock 😃
finally i see the error with your comment. ;=)

0 Karma

tomasnelson
Explorer

I think I expressed myself wrong, I leave a more explicit picture about the error:alt text

0 Karma

woodcock
Esteemed Legend

You probably forgot the comma between the field namd and the time expression. So you have something like eval foo=strfime(bar "%Y-%m-%d %H:%M") instead of eval foo=strfime(bar, "%Y-%m-%d %H:%M").

0 Karma

adonio
Ultra Champion

hello tomasnelson,
remove the singe quotes ' ' all you need is this: eval blah = srftime(_time, ”%Y-%m-%d %H:%M”)

0 Karma

adonio
Ultra Champion

hello tomasnelson,
remove the singe quotes ' ' all you need is this: eval blah = srftime(_time, ”%Y-%m-%d %H:%M”)

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...