_raw data exported from a search query. This not the actual raw data stream from the sending device, correct? This is the data after any default rules have been applied at index time.
Correct. The _raw field contains the data in the event that is indexed in Splunk. This data can differ from the raw data of the sending device depending on the index-time processing has been applied to it.