Answer by warren for How Splunk field contains double quote

| makeresults 
| eval bub="hell\"o"
| table bub

Puts a double-quote mark right in the middle of the bub field

If you want to search for the double-quote mark, use | where match() like this:

| where match(bub,"\"")

from User warren – Stack Overflow https://stackoverflow.com/questions/74063311/how-splunk-field-contains-double-quote/74063544#74063544
via IFTTT