Splunk Search

Why is my splunk search not working?

mikeyty07
Communicator

i have index=main  user=Local Domain\abc it wont search any result but if i search with index=main  user=Local Domain\\abc it works,
i tried rex as well but it didnt work for my dashboard as it wont display any search, any solution to search without adding another \ to the search

0 Karma

somesoni2
Revered Legend

Have you tried this?

index=main  user="Local Domain\abc"
0 Karma

mikeyty07
Communicator

yes. I tried that too, but the search is happening for
 index=main user="Local Domain\\abc"
which i tried to regex but it didnt display on dashboard but i can see the new field being created with. from dashboard i wanted to send the selected as token to get stats.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...