Outputs the raw text (_raw) of results into the _xml field.
outputtext command was created as an internal mechanism to render event texts for output.
By default, the command xml-escapes the text of events and copies them to the _xml field. If usexml=false,
outputtext simply copies the text of events to the _xml field.
outputtext is a reporting command, the command will pull all events to the search head and cause the output to show in the statistics UI if used in the web interface.
- Syntax: usexml=<bool>
- Description: If usexml is set to true (the default), the copy of the _raw field in _xml is xml escaped. If usexml is set to false, the _xml field is an exact copy of _raw.
Output the "_raw" field of your current search into "_xml".
... | outputtext
Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the outputtext command.
This documentation applies to the following versions of Splunk Cloud™: 6.6.3, 7.0.0, 7.0.2, 7.0.5, 7.0.3, 7.0.8, 7.0.11, 7.1.3, 7.1.6, 7.2.3, 7.2.4, 7.2.6, 7.2.7