Splunk Search

Why do I receive "Error in 'eval' command: The expression is malformed. An unexpected character is reached at '”%Y-%m-%d %H:%M”)'." in my Splunk Light search?

tomasnelson
Explorer

Hi everyone !
I am a new user in Splunk (Great application and these days very useful); I read this document and I tried to reproduce the search but in my Splunk Free it does not work, reporting this error: Error in 'eval' command: The expression is malformed. An unexpected character is reached at '”%Y-%m-%d %H:%M”)'.

There is some limitation with my version? or the article is have something wrong ? I can not identify the solution...
please help...!!!!

https://www.splunk.com/blog/2016/08/12/detecting-early-signs-of-compromise-using-windows-sysinternal...

0 Karma
1 Solution

woodcock
Esteemed Legend

You have the @!#$%^&* Microsoft Windows left-and-right double-quotes ( and )instead of the correct ambiguous one ( " ).

View solution in original post

0 Karma

woodcock
Esteemed Legend

You have the @!#$%^&* Microsoft Windows left-and-right double-quotes ( and )instead of the correct ambiguous one ( " ).

0 Karma

tomasnelson
Explorer

Thanks a lot..... woodcock 😃
finally i see the error with your comment. ;=)

0 Karma

tomasnelson
Explorer

I think I expressed myself wrong, I leave a more explicit picture about the error:alt text

0 Karma

woodcock
Esteemed Legend

You probably forgot the comma between the field namd and the time expression. So you have something like eval foo=strfime(bar "%Y-%m-%d %H:%M") instead of eval foo=strfime(bar, "%Y-%m-%d %H:%M").

0 Karma

adonio
Ultra Champion

hello tomasnelson,
remove the singe quotes ' ' all you need is this: eval blah = srftime(_time, ”%Y-%m-%d %H:%M”)

0 Karma

adonio
Ultra Champion

hello tomasnelson,
remove the singe quotes ' ' all you need is this: eval blah = srftime(_time, ”%Y-%m-%d %H:%M”)

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...