Splunk Search

how to replace \ with \\ in eval statement

reney44
Engager

i expect var1="d:\test\data.csv" but i got

it shows mismatch or missing closing parenthesis

var="d:\test\data.csv"
|eval var1=replace(var,"\","\\")

Tags (2)
0 Karma
1 Solution

javiergn
Super Champion

If all you are trying to do is to replace one backslash with two then you can do the following:

| stats count
| eval var="d:\\test\\data.csv"
| eval var1=replace(var,"\\\\","\\\\\\")

(Ignore the stats count as I used this to test)
Output:

alt text

Take a look at the following links if you want to read more about it:

https://docs.splunk.com/Documentation/Splunk/latest/Search/SPLandregularexpressions#Backslash_charac...
https://answers.splunk.com/answers/623193/tricky-behavior-of-escaping-backslash-in-regex.html#answer...

Regards,
J

View solution in original post

0 Karma

javiergn
Super Champion

If all you are trying to do is to replace one backslash with two then you can do the following:

| stats count
| eval var="d:\\test\\data.csv"
| eval var1=replace(var,"\\\\","\\\\\\")

(Ignore the stats count as I used this to test)
Output:

alt text

Take a look at the following links if you want to read more about it:

https://docs.splunk.com/Documentation/Splunk/latest/Search/SPLandregularexpressions#Backslash_charac...
https://answers.splunk.com/answers/623193/tricky-behavior-of-escaping-backslash-in-regex.html#answer...

Regards,
J

0 Karma

p_gurav
Champion
0 Karma
Get Updates on the Splunk Community!

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

Splunk New Course Releases for a Changing World

Every day, the world feels like it’s moving faster with new technological breakthroughs, AI innovation, and ...