<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk issue to display some special characters in the stats table? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-issue-to-display-some-special-characters-in-the-stats/m-p/677510#M18654</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Is this been resolved? Would like to know the solution.&lt;/P&gt;</description>
    <pubDate>Wed, 14 Feb 2024 03:03:09 GMT</pubDate>
    <dc:creator>amiruln</dc:creator>
    <dc:date>2024-02-14T03:03:09Z</dc:date>
    <item>
      <title>Splunk issue to display some special characters in the stats table?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-issue-to-display-some-special-characters-in-the-stats/m-p/614088#M13984</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;
&lt;P&gt;I need your help to understand and to solve an issue we discovered with Splunk. This issue seems to be a limitation or a bug of Splunk Enterprise :&lt;BR /&gt;&lt;BR /&gt;We work with microsoft sysmon data, and sometimes we have events with the value of a command executed in prompt.&lt;BR /&gt;Splunk reports the exact value of the command executed in the raw event :&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raphy_0-1663841845478.png" style="width: 841px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21604i3AAED36D6404AECD/image-dimensions/841x152?v=v2" width="841" height="152" role="button" title="Raphy_0-1663841845478.png" alt="Raphy_0-1663841845478.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And the value extracted by Splunk for the field&amp;nbsp;CommandLine is the following :&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raphy_1-1663842081750.png" style="width: 460px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21605iE1EB0D0121E39574/image-dimensions/460x216?v=v2" width="460" height="216" role="button" title="Raphy_1-1663842081750.png" alt="Raphy_1-1663842081750.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;However, when I want to display the&amp;nbsp;CommandLine&amp;nbsp; field in a table or a stats table, then I get that. See the last row of the table for our CommandLine example :&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-09-22 12_10_10-MicrosoftTeams-image (3).png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21606i3EA174A2064924A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-09-22 12_10_10-MicrosoftTeams-image (3).png" alt="2022-09-22 12_10_10-MicrosoftTeams-image (3).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Splunk replaces my quotes by HTML encoded charactersin the table.&lt;BR /&gt;&lt;BR /&gt;However, the strange thing is not that Splunk replaces everytime special characters by HTML character, Splunk only replaces the special character by HTML characters for some commands executed.&amp;nbsp;&lt;BR /&gt;Just check the examples below to understand the issue :&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-09-22 12_03_02-MicrosoftTeams-image (1).png" style="width: 785px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21607iA4597C5292A210B4/image-dimensions/785x226?v=v2" width="785" height="226" role="button" title="2022-09-22 12_03_02-MicrosoftTeams-image (1).png" alt="2022-09-22 12_03_02-MicrosoftTeams-image (1).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-09-22 12_07_48-MicrosoftTeams-image (2).png" style="width: 822px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21608i7626942BD8B734AA/image-dimensions/822x260?v=v2" width="822" height="260" role="button" title="2022-09-22 12_07_48-MicrosoftTeams-image (2).png" alt="2022-09-22 12_07_48-MicrosoftTeams-image (2).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Depending on whether we use some texts that Splunk seems to do not like or not, Splunk will encode my special characters in the table or not.&lt;BR /&gt;The texts in the command executed, that generates the Splunk HTML encoding in table or stats are the followings :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;lt;script&amp;gt;
or
vbsscript:
or
javascript&amp;amp;colon;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Otherwise, if I put another text, in the command like "blablascript:" or "script:" I do not have the issue.&lt;BR /&gt;&lt;BR /&gt;Could someone please help us to understand from where this issue may come ?&lt;BR /&gt;Is it a Splunk limitation/bug or just something that we need to configure somewhere ?&lt;/P&gt;
&lt;P&gt;Great Thanks to you by advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 15:14:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-issue-to-display-some-special-characters-in-the-stats/m-p/614088#M13984</guid>
      <dc:creator>Raphy</dc:creator>
      <dc:date>2022-09-22T15:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk issue to display some special characters in the stats table?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-issue-to-display-some-special-characters-in-the-stats/m-p/677510#M18654</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Is this been resolved? Would like to know the solution.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 03:03:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-issue-to-display-some-special-characters-in-the-stats/m-p/677510#M18654</guid>
      <dc:creator>amiruln</dc:creator>
      <dc:date>2024-02-14T03:03:09Z</dc:date>
    </item>
  </channel>
</rss>

