Splunk Search

Why do I receive "Error in 'eval' command: The expression is malformed. An unexpected character is reached at '”%Y-%m-%d %H:%M”)'." in my Splunk Light search?

tomasnelson
Explorer

Hi everyone !
I am a new user in Splunk (Great application and these days very useful); I read this document and I tried to reproduce the search but in my Splunk Free it does not work, reporting this error: Error in 'eval' command: The expression is malformed. An unexpected character is reached at '”%Y-%m-%d %H:%M”)'.

There is some limitation with my version? or the article is have something wrong ? I can not identify the solution...
please help...!!!!

https://www.splunk.com/blog/2016/08/12/detecting-early-signs-of-compromise-using-windows-sysinternal...

0 Karma
1 Solution

woodcock
Esteemed Legend

You have the @!#$%^&* Microsoft Windows left-and-right double-quotes ( and )instead of the correct ambiguous one ( " ).

View solution in original post

0 Karma

woodcock
Esteemed Legend

You have the @!#$%^&* Microsoft Windows left-and-right double-quotes ( and )instead of the correct ambiguous one ( " ).

0 Karma

tomasnelson
Explorer

Thanks a lot..... woodcock 😃
finally i see the error with your comment. ;=)

0 Karma

tomasnelson
Explorer

I think I expressed myself wrong, I leave a more explicit picture about the error:alt text

0 Karma

woodcock
Esteemed Legend

You probably forgot the comma between the field namd and the time expression. So you have something like eval foo=strfime(bar "%Y-%m-%d %H:%M") instead of eval foo=strfime(bar, "%Y-%m-%d %H:%M").

0 Karma

adonio
Ultra Champion

hello tomasnelson,
remove the singe quotes ' ' all you need is this: eval blah = srftime(_time, ”%Y-%m-%d %H:%M”)

0 Karma

adonio
Ultra Champion

hello tomasnelson,
remove the singe quotes ' ' all you need is this: eval blah = srftime(_time, ”%Y-%m-%d %H:%M”)

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...