Splunk Search

Why is my splunk search not working?

mikeyty07
Communicator

i have index=main  user=Local Domain\abc it wont search any result but if i search with index=main  user=Local Domain\\abc it works,
i tried rex as well but it didnt work for my dashboard as it wont display any search, any solution to search without adding another \ to the search

0 Karma

somesoni2
Revered Legend

Have you tried this?

index=main  user="Local Domain\abc"
0 Karma

mikeyty07
Communicator

yes. I tried that too, but the search is happening for
 index=main user="Local Domain\\abc"
which i tried to regex but it didnt display on dashboard but i can see the new field being created with. from dashboard i wanted to send the selected as token to get stats.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...