Splunk Search

mismatch '[' in search

dgadjov
Explorer

Running this through the Splunk search I get no errors. However when I put this search in my Advance XML I get: mismatch '['

source="/usr/local/splunk/splunk_test/test_data/sample_data" _time=[ search source="/usr/local/splunk/splunk_test/test_data/sample_data" | stats latest(_time) as new_data | return $new_data] | table * | replace "Failed" with 0 "Passed" with 100 | appendpipe [stats avg(*) as *] | replace 0 with "Failed" 100 with "Passed"
Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

My guess is your "return $new_value]" got turned into "return " because there was no such variable to substitute. Try escaping the dollar sign with another dollar sign like this: "return $$new_value]"

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

My guess is your "return $new_value]" got turned into "return " because there was no such variable to substitute. Try escaping the dollar sign with another dollar sign like this: "return $$new_value]"

martin_mueller
SplunkTrust
SplunkTrust

$$ gets turned into $, much like \\ getting turned into \ in regular expressions. With a single dollar sign it's trying to substitute variables such as $foo$.

0 Karma

dgadjov
Explorer

Wow that works! What does the double dollar sign do to make this work?

0 Karma

vincesesto
Communicator

Hey dgagjov,

My guess would be that the characters in the search that you are doing are being recognized as xml tags and is confusing things. If you enclose your search in <![CDATA[ and ]]>, it will allow you to place anything into your search without there being any issue.

Eg:
<![CDATA[
source="/usr/local/splunk/splunk_test/test_data/sample_data" _time=[ search source="/usr/local/splunk/splunk_test/test_data/sample_data" | stats latest(_time) as new_data | return $new_data] | table * | replace "Failed" with 0 "Passed" with 100 | appendpipe [stats avg(*) as *] | replace 0 with "Failed" 100 with "Passed"
]]>

Let me know if you need me to elaborate, and let me know if this does not work.

Regards Vince

0 Karma

dgadjov
Explorer

This is actually the first thing that I tried when I got this error. With or without the CDATA the mismatch will occur.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...