Helpful tips and tricks for Splunk.
- Replace backslash:
eval var=replace(<var>, "\\\\", <replacement>)
Splunk uses the | ("or bar") as a means to break up statements. Instead of using one long string of statements, consider deliminating | [statement] on seperate lines.