Splunk Search

problem with field that contains character "\\"

are0002
Path Finder

Hi,

I have a log with this type of content: domain\\user. I have extracted this info with field extraction called src_user.

When I do a search with src_user=* | table src_user, the response shows domain\user instead of domain\\user. One of the \ characters is stripped.

Then when I am doing a searchFieldsToDisplay to get src_user value I get domain\user and I can not set a new search with this searchField value.

Does anyone know how to solve this?

Regards

Tags (2)

fdi01
Motivator

trying to see your regular expression because you must be missing something, and is the problem that must come. and also check if you have not escape "\" s inside.
without your expression regular and an example of data I do not guess more.

0 Karma

woodcock
Esteemed Legend

If it is exactly as you have described, it has to be a bug and I would open a Support Case with Splunk right away.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...