<?xml version="1.0" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
	<channel>
		<title>Splunk Base : SplunkGeneral : #3749</title>
		<link>http://www.splunk.com/support/forum:SplunkGeneral/3749</link>
		<description></description>
		<pubDate>Mon, 13 Feb 2012 12:08:40 PST</pubDate>
		<lastBuildDate>Mon, 13 Feb 2012 12:08:40 PST</lastBuildDate>
		<language>en-us</language>
		<copyright>http://creativecommons.org/licenses/by-nc-nd/2.5/</copyright>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/13670</link>
			<description>&lt;p&gt;I just upgaded to 4.0.10 and that seems to have fixed the problems I was having with the escaping &amp;amp; quoting.&lt;br /&gt;
Thanks.&lt;/p&gt;

</description>
			<pubDate>Tue, 16 Mar 2010 06:01:01 PDT</pubDate>
			<author>msallman</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/13670</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/13500</link>
			<description>&lt;p&gt;This is serious problem for me. I just noticed that I was missing alerts on a whole class of errors. Are there any workarounds or expectations as to when this will be fixed?&lt;/p&gt;

</description>
			<pubDate>Fri, 05 Mar 2010 12:14:39 PST</pubDate>
			<author>jerrybrennock2</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/13500</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/13109</link>
			<description>&lt;p&gt;yeah, i know :)&lt;/p&gt;

</description>
			<pubDate>Thu, 11 Feb 2010 18:01:34 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/13109</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/13104</link>
			<description>&lt;p&gt;LOL @ us for fixing the issue with NOT but not fixing the other issues :D&lt;/p&gt;

</description>
			<pubDate>Thu, 11 Feb 2010 16:25:12 PST</pubDate>
			<author>araitz</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/13104</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/13099</link>
			<description>&lt;p&gt;my understanding is that parts of the problem were fixed in 4.0.9--specifically queries with &amp;quot;NOT&amp;quot; in them. initially (when writing the release notes for 4.0.9), i thought the bugfix applied to the entire issue, but it didn't.&lt;/p&gt;

</description>
			<pubDate>Thu, 11 Feb 2010 14:07:05 PST</pubDate>
			<author>rachel</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/13099</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/13098</link>
			<description>&lt;p&gt;Ok, thanks.&lt;/p&gt;

</description>
			<pubDate>Thu, 11 Feb 2010 13:26:00 PST</pubDate>
			<author>msallman</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/13098</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/13093</link>
			<description>&lt;p&gt;The problem is not fixed in 4.0.9, I can confirm this.  I believe the issue is supposed to be re-fixed in 4.0.10, I will try to confirm that this is the case.&lt;/p&gt;

</description>
			<pubDate>Thu, 11 Feb 2010 12:31:12 PST</pubDate>
			<author>araitz</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/13093</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/13086</link>
			<description>&lt;p&gt;they're not available publicly. it would be helpful to have an example of a query that behaves that way, and you can either open a support case with it (it should be easy enough to verify it's a bug) or you post it here.&lt;/p&gt;

</description>
			<pubDate>Thu, 11 Feb 2010 11:58:31 PST</pubDate>
			<author>gkanapathy</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/13086</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/13081</link>
			<description>&lt;p&gt;Are those issues accessible anywhere on the website? &lt;br /&gt;
It seems from the descriptions in the release notes that it just affected &amp;quot;NOT&amp;quot; queries? Or that those were the only ones that were fixed?&lt;br /&gt;
The reason I ask is that we have a couple of queries that broke with the same problem (extra escaping of quotes and/or extra quotes, though ours doesn't have any &amp;quot;NOT&amp;quot;s). I just upgraded to 4.0.9 and the problem doesn't seem to have been fixed. For us, anyway. :-)&lt;/p&gt;

</description>
			<pubDate>Thu, 11 Feb 2010 11:30:17 PST</pubDate>
			<author>msallman</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/13081</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/13076</link>
			<description>&lt;p&gt;Looks like yes: &lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/ReleaseNotes/4.0.9&quot;&gt;http://www.splunk.com/base/Documentation/latest/ReleaseNotes/4.0.9&lt;/a&gt;&lt;/p&gt;

</description>
			<pubDate>Thu, 11 Feb 2010 10:18:11 PST</pubDate>
			<author>gkanapathy</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/13076</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/13071</link>
			<description>&lt;p&gt;Is this one of the issues (SPL-26944, SPL-28136, SPL-28640) that were fixed in release 4.0.9?&lt;/p&gt;

</description>
			<pubDate>Thu, 11 Feb 2010 09:33:04 PST</pubDate>
			<author>msallman</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/13071</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/12188</link>
			<description>&lt;p&gt;Nope, you did everything right!  I will try to remember to update this post when the bug is fixed, but to be extra sure you can email support at splunk dot com, let them know you are having the issue and ask them to let you know when it is fixed.&lt;/p&gt;

</description>
			<pubDate>Wed, 16 Dec 2009 14:48:50 PST</pubDate>
			<author>araitz</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/12188</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/12186</link>
			<description>&lt;p&gt;Ok, just wanted to make sure I wasn't doing something wrong.&lt;/p&gt;

</description>
			<pubDate>Wed, 16 Dec 2009 13:54:18 PST</pubDate>
			<author>scarolan108</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/12186</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/12185</link>
			<description>&lt;p&gt;This is a known issue and should be fixed in an upcoming service release - sorry for the inconvenience, it bugs me too!&lt;/p&gt;

</description>
			<pubDate>Wed, 16 Dec 2009 13:44:28 PST</pubDate>
			<author>araitz</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/12185</guid>
		</item>
		<item>
			<title>Splunk bug with backslash and quotes - escape character \</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/3749/12181</link>
			<description>&lt;p&gt;I have a relatively simple search, which includes a phrase enclosed in double quotes.  For example:&lt;/p&gt;

&lt;p&gt;error OR failed OR severe OR ( sourcetype=access_* ( 404 OR 500 OR 503 ) ) NOT &amp;quot;illegal user&amp;quot;&lt;/p&gt;

&lt;p&gt;When I type in the search manually it works fine.  When I save it Splunk inserts escape characters before each of the quotes, so that the next time I pull up the search it fails and shows zero results.  I have to manually delete the backslashes to get it to work again.  Older versions of splunk did not do this.&lt;/p&gt;

&lt;p&gt;Please let me know what I need to do to fix this.  It's extremely annoying to have to delete the backslashes each time.&lt;/p&gt;

</description>
			<pubDate>Wed, 16 Dec 2009 12:38:50 PST</pubDate>
			<author>scarolan108</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/3749/12181</guid>
		</item>
	</channel>
</rss>

