Splunk Enterprise

Why is Colon Character in JS not working?

rkeq0515
Path Finder

I am trying to use a colon ( : ) in my js file; however, I do not see results when I use the colon.  I verified that the command works with the colon when I run it within a Search window.   I also have it working without the colon in the js file.  I just can't seem to use the colon in the js file. 

The following code in my js file does not work.

 

... | search (path IN (\"*:\\windows\\*\")) | stats count

 

 

The following code in my js file works.

 

... | search (path IN (\"*\\windows\\*\")) | stats count

 

 

I tried to escape it like I did the double-quotes, but that did not work.  Is there a way to use the colon in the js file?

 

Thanks 

0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@rkeq0515 - I always try multiple try-and-error when dealing with \ (backward slash).

One of these should work:

... | search path IN (\"*:\\windows\\*\") | stats count
... | search path IN (\"*:\\\windows\\\*\") | stats count
... | search path IN (\"*:\\\\windows\\\\*\") | stats count

(3 or 4 slashes should work)

 

I hope this helps!!!

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@rkeq0515 - I always try multiple try-and-error when dealing with \ (backward slash).

One of these should work:

... | search path IN (\"*:\\windows\\*\") | stats count
... | search path IN (\"*:\\\windows\\\*\") | stats count
... | search path IN (\"*:\\\\windows\\\\*\") | stats count

(3 or 4 slashes should work)

 

I hope this helps!!!

0 Karma

rkeq0515
Path Finder

Thank you!  The 4 back slashes worked.  I was focused on the colon since 2 back slashes were working.  However, I see that it wasn't providing the correct data.

0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...