Splunk Search

Why is my splunk search not working?

mikeyty07
Communicator

i have index=main  user=Local Domain\abc it wont search any result but if i search with index=main  user=Local Domain\\abc it works,
i tried rex as well but it didnt work for my dashboard as it wont display any search, any solution to search without adding another \ to the search

0 Karma

somesoni2
Revered Legend

Have you tried this?

index=main  user="Local Domain\abc"
0 Karma

mikeyty07
Communicator

yes. I tried that too, but the search is happening for
 index=main user="Local Domain\\abc"
which i tried to regex but it didnt display on dashboard but i can see the new field being created with. from dashboard i wanted to send the selected as token to get stats.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...