Splunk regex escape character. To avoid using extra escaping backslashes in your searches, you can use the octal code \134 or the hexadecimal code \x5c in your regular expression. So, let's say I have a raw value of Fred Smith: my_key=name my_value="Fred Smith" Apr 3, 2023 · This character is used to escape any special character that may be used in the regular expression. Jul 30, 2015 · Splunk best practices say to use key/value pairs. Dec 3, 2019 · Hi experts, I wanted to escape the backslash "\" from the below logs, and capture the status code. Mar 7, 2018 · As far as I'm aware, there is some double escaping going on, first from the search bar to the regex and then of course inside the regex. These codes are equivalent to the backslash character and get around the need to double-escape backslashes. Jul 18, 2025 · To avoid using extra escaping backslashes in your searches, you can use the octal code \134 or the hexadecimal code \x5c in your regular expression. Example: Splunk? matches with the string “Splunk?” This character matches with any possible character, as it is always used as a wildcard character. Example: Splunk* matches with “Splunk”, “Splunkster” or “Splunks”. you need \\ in your regex, to achieve that, you need \\\\ in the splunk search bar in the rex command. Jan 20, 2025 · Anyway, when you need to escape a backslash in Splunk in a regex that runs in regex101, you have to add one ot two additional backslashes in Splunk every time you jave a backslash. It also says to wrap values in quotes if they contain spaces. . The output should be like this. qmti ccvlvdt mdfs squsxb jfyzrm itopnww jlbxwjk ohyyh fsttwc ttya