Hi,
Take a look at:
http://docs.splunk.com/Documentation/Splunk/6.1/SearchReference/search
In the Quotes and escaping characters section:
The backslash character () is used to escape quotes, pipes, and itself. Backslash escape sequences are still expanded inside quotes. For example:
The sequence \| as part of a search will send a pipe character to the command, instead of having the pipe split between commands.
The sequence \" will send a literal quote to the command, for example for searching for a literal quotation mark or inserting a literal quotation mark into a field using rex.
The \\ sequence will be available as a literal backslash in the command.
Hope that helps.
... View more