I'm currently creating a search and in my search I entered the following
source="FileName.csv" \ OR SMS
In the results it shows events with a Single "\" and double "\". I need to show results with two "\" not only one.
I've tried:
\
"\"
punct=*\*
But still it shows only results with only one "\". What can be done so the results show results where there is actually two "\"?
Regards
use "\" for single slash and use "\\" for double slash. Because splunk use slash as an escape character.
Use \\.
use "\" for single slash and use "\\" for double slash. Because splunk use slash as an escape character.
Thank you for the help.