Splunk Search

Using a literal pipe "|" character in an extracted regex field

jbrenner
Path Finder

I'm creating an extracted field using a regex, and I want to use a literal pipe "|" character in the regex.
My understanding is to use a backspace as an escape character as follows:

\|

When I save the regex and return to it, however, the backslash has been removed.
What am I doing wrong?

Thanks,
Jonathan

Tags (1)
0 Karma

jbrenner
Path Finder

Hi,

I don't know what I was doing wrong, but after trying some different things, it stopped stripping out the escape characters.
I think I must have doing something wrong in the UI.
To answer your question, though, I was selecting the dropdown that says "Event Actions" and selecting "Extract Fields"

Thanks for responding,
Jonathan

0 Karma

somesoni2
Revered Legend

Glad your issue is resolved. If there are no other followup (related) questions, they you can close this question by accepting this as an answer.

0 Karma

jbrenner
Path Finder

Sorry. meant to say "backslash," not "backspace" 🙂

0 Karma

somesoni2
Revered Legend

What's the full regex that you're using? How are you saving it, using IFX (interactive field extraction wizard) OR directory through settings?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...