<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to remove extra characters from an indexed event? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415329#M169265</link>
    <description>&lt;P&gt;Hehe, I read that, but I wasnt clear to me that you meant that... which might be a non-native-English issue with me, sorry &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 22 May 2018 21:57:10 GMT</pubDate>
    <dc:creator>xpac</dc:creator>
    <dc:date>2018-05-22T21:57:10Z</dc:date>
    <item>
      <title>How to remove extra characters from an indexed event?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415325#M169261</link>
      <description>&lt;P&gt;Good afternoon&lt;/P&gt;

&lt;P&gt;Is there a way to remove extra characters (\xAF) from already indexed events such as this one:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;20182018--0505--2222  1111::3939::1818,,937937 [ [4747] ] ERRORERROR  -- 
  ErrorError  MessageMessage::  OneOne  oror  moremore  errorserrors  occurredoccurred..
 \xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xA \xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF
Calling assembly Name/Source: Sms.Utilities, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null/mscorlib
\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF
Stack Trace: 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 20:25:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415325#M169261</guid>
      <dc:creator>Bellamar10</dc:creator>
      <dc:date>2018-05-22T20:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove extra characters from an indexed event?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415326#M169262</link>
      <description>&lt;P&gt;Hi Bellamar10,&lt;/P&gt;

&lt;P&gt;try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval foo="20182018--0505--2222 1111::3939::1818,,937937 [ [4747] ] ERRORERROR -- 
ErrorError MessageMessage:: OneOne oror moremore errorserrors occurredoccurred..
\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xA \xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF
Calling assembly Name/Source: Sms.Utilities, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null/mscorlib
\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF\xAF" 
| rex mode=sed field=foo "s/\\\xAF//g"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The first 2 lines are used to create an event and the important command is the last line which will remove the characters &lt;CODE&gt;\xAF&lt;/CODE&gt; from your &lt;STRONG&gt;search result&lt;/STRONG&gt;. But remember the characters will still be in the &lt;CODE&gt;_raw&lt;/CODE&gt; event &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 20:35:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415326#M169262</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-05-22T20:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove extra characters from an indexed event?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415327#M169263</link>
      <description>&lt;P&gt;Just to add on this - because you explicitely asked for "already indexed events" - you can do this like shown above, but it will not be persistent. Data, once indexed, can not be changed afterwards (permanently), only in every search again and again.&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 20:48:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415327#M169263</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-22T20:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove extra characters from an indexed event?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415328#M169264</link>
      <description>&lt;P&gt;HeHE, did you read my answer to the end? I already mentioned that in my answer &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 20:54:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415328#M169264</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-05-22T20:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove extra characters from an indexed event?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415329#M169265</link>
      <description>&lt;P&gt;Hehe, I read that, but I wasnt clear to me that you meant that... which might be a non-native-English issue with me, sorry &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 21:57:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415329#M169265</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-22T21:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove extra characters from an indexed event?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415330#M169266</link>
      <description>&lt;P&gt;let's call it lost in translation from &lt;CODE&gt;swiss german - german - english&lt;/CODE&gt; at the writer side and &lt;CODE&gt;english - german&lt;/CODE&gt; on the reader side &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 22:05:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-extra-characters-from-an-indexed-event/m-p/415330#M169266</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-05-22T22:05:18Z</dc:date>
    </item>
  </channel>
</rss>

