<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Raw data removed space delimiter when using $result.raw$ in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446741#M77720</link>
    <description>&lt;P&gt;Great!  Be sure to come back here and click &lt;CODE&gt;Accept&lt;/CODE&gt; to close the question.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jul 2019 05:26:49 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-07-11T05:26:49Z</dc:date>
    <item>
      <title>Raw data removed space delimiter when using $result.raw$</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446734#M77713</link>
      <description>&lt;P&gt;Below is the search result:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;1561992871526   CRMCGAES42-CSFBAES42    8=FIX.4.2&amp;#1;9=354&amp;#1;35=8&amp;#1;34=2175&amp;#1;43=N&amp;#1;49=CSFBAES42&amp;#1;50=EXECSVC-26-CANADA&amp;#1;52=20190701-14:54:31&amp;#1;56=CRMCGAES42&amp;#1;57=NCJM&amp;#1;97=N&amp;#1;6=0.000000&amp;#1;11=7266812-1-075431381&amp;#1;14=0&amp;#1;15=CAD&amp;#1;17=28314234931&amp;#1;20=0&amp;#1;22=2&amp;#1;31=0.000000&amp;#1;32=0&amp;#1;37=3O1951000070120&amp;#1;38=38&amp;#1;39=8&amp;#1;40=2&amp;#1;44=109.270000&amp;#1;48=2754383&amp;#1;54=1&amp;#1;55=RY.TO&amp;#1;58=ExchangeClosed Trading holiday in CA &amp;#1;60=20190701-14:54:31&amp;#1;75=20190701&amp;#1;113=N&amp;#1;150=8&amp;#1;151=0&amp;#1;10=072&amp;#1;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, when I've used $result.raw$ in the email body, all the spaces are gone.  Please help.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;1561992871526 CRMCGAES42-CSFBAES42 IN 8=FIX.4.29=35435=834=217543=N49=CSFBAES4250=EXECSVC-26-CANADA52=20190701-14:54:3156=CRMCGAES4257=NCJM97=N6=0.00000011=7266812-1-07543138114=015=CAD17=2831423493120=022=231=0.00000032=037=3O195100007012038=3839=840=244=109.27000048=275438354=155=RY.TO58=ExchangeClosed Trading holiday in CA 60=20190701-14:54:3175=20190701113=N150=8151=010=072
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;All I want to email the result but do not want to show the search string...I am looking around but did not find anything for that.  So now I just want to attach the result (_raw) in the email w/o the result link.  However, I ran to another issue with the delimiter.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 21:01:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446734#M77713</guid>
      <dc:creator>elhuynh</dc:creator>
      <dc:date>2019-07-01T21:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Raw data removed space delimiter when using $result.raw$</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446735#M77714</link>
      <description>&lt;P&gt;the first search result that you are showing is what? just the  _raw event or the result of a search string?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 07:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446735#M77714</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-07-03T07:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Raw data removed space delimiter when using $result.raw$</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446736#M77715</link>
      <description>&lt;P&gt;Hi Sukisen,&lt;/P&gt;

&lt;P&gt;The first result is the result of a search string.  When the alert is triggered I wanted to send out an email with the first result but "link to results" option showing the search string which I do not want.  I've been looking around for a solution but so far I did not find any.  I came up with an idea to include $result$ token in the body of the email but all the space delimiters were removed which make it's difficult to read the result.&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 17:52:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446736#M77715</guid>
      <dc:creator>elhuynh</dc:creator>
      <dc:date>2019-07-03T17:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Raw data removed space delimiter when using $result.raw$</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446737#M77716</link>
      <description>&lt;P&gt;Those are not spaces, they are some other character.  You need to figure out what the characters are and replace them with spaces like this (replace &lt;CODE&gt;12345&lt;/CODE&gt; with the actual hexadecimal value for your character):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex mode=sed "s/\x12345/ /g"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 04 Jul 2019 00:34:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446737#M77716</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-04T00:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Raw data removed space delimiter when using $result.raw$</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446738#M77717</link>
      <description>&lt;P&gt;I've verified the logs and the delimiter is ^A as below.&lt;BR /&gt;
18=1^A48=BYWMQJ2^A20=0^A21=3^A20001=254900WNB33E53292541^A22=2^A54=1^A55=AYX^A29=1^A59=0^A10=050^A&lt;/P&gt;

&lt;P&gt;Hex value of ^ is 5E and A is 41.  I did what you've suggested but not sure if it's right syntax since it does not work.&lt;/P&gt;

&lt;P&gt;index=fix sourcetype="fix:app:app_log" "39=8"AND "58=*"&lt;BR /&gt;
| rex mode=sed "s/\x5E41/ /g"&lt;BR /&gt;
| dedup _raw&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 17:36:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446738#M77717</guid>
      <dc:creator>elhuynh</dc:creator>
      <dc:date>2019-07-10T17:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Raw data removed space delimiter when using $result.raw$</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446739#M77718</link>
      <description>&lt;P&gt;should be ASCII=1 so try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex mode=sed "s/\x01/ /g"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 10 Jul 2019 18:25:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446739#M77718</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-10T18:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Raw data removed space delimiter when using $result.raw$</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446740#M77719</link>
      <description>&lt;P&gt;It worked.  Thanks woodcock!!  I found a post to sed multi-characters as below but it did not work.&lt;/P&gt;

&lt;P&gt;rex mode=sed "s/^A/ /g"&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 22:11:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446740#M77719</guid>
      <dc:creator>elhuynh</dc:creator>
      <dc:date>2019-07-10T22:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: Raw data removed space delimiter when using $result.raw$</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446741#M77720</link>
      <description>&lt;P&gt;Great!  Be sure to come back here and click &lt;CODE&gt;Accept&lt;/CODE&gt; to close the question.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 05:26:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Raw-data-removed-space-delimiter-when-using-result-raw/m-p/446741#M77720</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-11T05:26:49Z</dc:date>
    </item>
  </channel>
</rss>

