Splunk Cloud Platform

Search Reference



Outputs the contents of the _raw field to the _xml field.

The outputtext command was created as an internal mechanism to render event texts for output.


outputtext [usexml=<bool>]

Optional arguments

Syntax: usexml=<bool>
Description: If set to true, the copy of the _raw field in the _xml is escaped XML. If usexml is set to false, the _xml field is an exact copy of _raw.
Default: true


The outputtext command is a reporting command.

The outputtext command writes all search results to the search head. In Splunk Web, the results appear in the Statistics tab.


1. Output the _raw field into escaped XML

Output the "_raw" field of your current search into "_xml".

... | outputtext

See also


Last modified on 03 March, 2020
outputlookup   overlap

This documentation applies to the following versions of Splunk Cloud Platform: 8.2.2112, 8.2.2201, 8.2.2202, 9.0.2205, 8.2.2203, 9.0.2208, 9.0.2209, 9.0.2303, 9.0.2305, 9.1.2308 (latest FedRAMP release), 9.1.2312, 9.2.2403

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters