my understanding is that parts of the problem were fixed in 4.0.9--specifically queries with "NOT" in them. initially (when writing the release notes for 4.0.9), i thought the bugfix applied to the entire issue, but it didn't.
The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.
Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.
Forums: SplunkGeneral: Splunk bug with backslash and quotes - escape character \
Previous Topic: Splunk on AIX 6.1 | Next Topic: Reindex existing data?
LOL @ us for fixing the issue with NOT but not fixing the other issues :D
yeah, i know :)
This is serious problem for me. I just noticed that I was missing alerts on a whole class of errors. Are there any workarounds or expectations as to when this will be fixed?
I just upgaded to 4.0.10 and that seems to have fixed the problems I was having with the escaping & quoting.
Thanks.