Splunk Enterprise

Splunk issue to display some special characters in the stats table?

Raphy
Explorer

Hello Splunkers,

I need your help to understand and to solve an issue we discovered with Splunk. This issue seems to be a limitation or a bug of Splunk Enterprise :

We work with microsoft sysmon data, and sometimes we have events with the value of a command executed in prompt.
Splunk reports the exact value of the command executed in the raw event :

Raphy_0-1663841845478.png

And the value extracted by Splunk for the field CommandLine is the following :

Raphy_1-1663842081750.png

However, when I want to display the CommandLine  field in a table or a stats table, then I get that. See the last row of the table for our CommandLine example :

2022-09-22 12_10_10-MicrosoftTeams-image (3).png

Splunk replaces my quotes by HTML encoded charactersin the table.

However, the strange thing is not that Splunk replaces everytime special characters by HTML character, Splunk only replaces the special character by HTML characters for some commands executed. 
Just check the examples below to understand the issue :

2022-09-22 12_03_02-MicrosoftTeams-image (1).png

2022-09-22 12_07_48-MicrosoftTeams-image (2).png

Depending on whether we use some texts that Splunk seems to do not like or not, Splunk will encode my special characters in the table or not.
The texts in the command executed, that generates the Splunk HTML encoding in table or stats are the followings : 

 

 

 

 

<script>
or
vbsscript:
or
javascript&colon;

 

 

 

 


Otherwise, if I put another text, in the command like "blablascript:" or "script:" I do not have the issue.

Could someone please help us to understand from where this issue may come ?
Is it a Splunk limitation/bug or just something that we need to configure somewhere ?

Great Thanks to you by advance.

 



 

Labels (2)
0 Karma

amiruln
Engager

Hi,

 Is this been resolved? Would like to know the solution.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...