Splunk Search
Highlighted

how do i search for the ? character?

Splunk Employee
Splunk Employee

"?" and escape permutations don't seem to work.

Highlighted

Re: how do i search for the ? character?

Legend

"?" seems to work just fine for me. Do you have an example of a search + log events that should match but don't?

You can also use regex and escape the question mark:

* | regex _raw="\?"

View solution in original post