Splunk Search

my search string is truncated after a question mark in a custom drilldown search

sabirmgd
Engager

my search string is truncated after a question mark in a custom drilldown search.

I have a statistic table that I made in a dashboard, and when I click in the row of that table, I have custom search.

so I go to Edit Drilldown -> Link to search and I choose custom.

the problem is: I am using regular expression in my custom search and when I click in the table row, it takes me to the new custom search but everything after the regular expression question mark is truncated.

here is my custome search:

host="myhost"   field1=$row.id$ 
|rex "\|mynewField:(?<newField>.*)\|"

however when I click and go to the custom search, the search appears is :

host="myhost"   field1=$row.id$ 
|rex "\|mynewField:(

so basically the question mark ?, and everything after is truncated. and I get Unbalanced quotes error

0 Karma

mayurr98
Super Champion

hey seems like it is URL encoding problem

edit your XML custom search as

  <drilldown>
          <link target="_blank">search?q=host="myhost"   field1=$row.id$ 
 |rex "\|mynewField:(%3F&lt;newField&gt;.*)\|"</link>
        </drilldown>

let me know if this helps!

mayurr98
Super Champion

If you deem a posted answer as valid and helpful to your solving of the issue, please accept said answer so that this question no longer appears open.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try replacing the question mark with its URL-encoded equivalent %3F.

---
If this reply helps you, Karma would be appreciated.

p_gurav
Champion

Hi sabirmgd,

Could you share XML in 101010 editor?

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...