Dashboards & Visualizations

Escaping input of fieldset text to allow search for word 'not'

martind
New Member

I'm having problems when searching for the word NOT in an input Field.

When searching for the text "DO NOT" in the text field i don't get any results. Clicking on the 'View Results' link i noticed splunk converts the input into id="DO" NOT.

How can i escape the Input Properly so the NOT word goes into the field search ( id="DO NOT" ) ? Example code below:

<form>
  <label>..</label>
  <searchTemplate>source="source.csv" MYFIELD=$id$ | timechart max(id)</searchTemplate>

  <fieldset>
    <input type="text" token="id" />
  </fieldset>

  <row>
    <chart>
      <title>Chart</title>
      <option name="charting.chart">line</option>
      <option name="charting.nullValueMode">gaps</option>
    </chart>
  </row>

</form>
Tags (1)
0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

Splunk only interprets NOT as such when it is fully capitalized.

You can try to quote the string:

MYFIELD="$id$"

You might also consider using eval to lowercase the value:

http://www.splunk.com/base/Documentation/latest/SearchReference/CommonEvalFunctions

Alternatively, you can instruct your users to use 'not', 'Not', or something similar.

View solution in original post

araitz
Splunk Employee
Splunk Employee

Splunk only interprets NOT as such when it is fully capitalized.

You can try to quote the string:

MYFIELD="$id$"

You might also consider using eval to lowercase the value:

http://www.splunk.com/base/Documentation/latest/SearchReference/CommonEvalFunctions

Alternatively, you can instruct your users to use 'not', 'Not', or something similar.

martind
New Member

that works perfectly 🙂 Thanks. Would be nice to have it somewhere in the docu, i searched for it but couldn't find anything about escaping (except XML Escaping)

0 Karma

araitz
Splunk Employee
Splunk Employee

Try the MYFIELD="$id$" first. If that fails, then let me know.

0 Karma

martind
New Member

i did not express myself clear, sorry. My Field value is from a text field.Do you know how to lower case that? I tried eval MYFIELD=lower($id$)

0 Karma

araitz
Splunk Employee
Splunk Employee

I added another (perhaps better) way to get Splunk to treat the value as a literal. Regarding your above question, try eval MYFIELD=lower(MYFIELD)

0 Karma

martind
New Member

can you give an example? tried: eval MYFIELD=lower("DO NOT")

0 Karma

martind
New Member

Thank's :). I did not know that Splunk is not case sensitive inside the text field

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...