Splunk Search

Why does transaction command seems to be encoding characters?

jplasencia
Explorer

Hello all, 

This is my first post here. I have been learning Splunk over the past few months and I am loving it.  I am running in to an interesting issue. 

I am using the transaction command to group events together.  An example of the queries below:

index::web ealiest=-30m
| transaction maxspan=3s

result: 

STARTED RECORD UPDATE: {"update"=>"contacts", "ordered"=>true, "updates"=>[{"q"=>{"_id"=>BSON::ObjectId('123456789')}

COMPLETED record update {"status": 200}

But if I append a table command to display the _raw field some of the characters are automatically encoded, as shown below:

index::web ealiest=-30m
| transaction maxspan=3s
| table _raw

result:


STARTED RECORD UPDATE: {"update"=>"contacts", "ordered"=>true, "updates"=>[{"q"=>{"_id"=>BSON::ObjectId('123456789')}

COMPLETED record update {&quotstatus&quot: 200}

 

I tried recreating this behavior by using makeresults, but in that case it works as I would expect. Does anyone have an idea of why this might be happening? 

 

Thanks,

Julio

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...