<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: formatted CDR files in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82307#M20906</link>
    <description>&lt;P&gt;Splunk tutorial: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Tutorial/WelcometotheSplunktutorial"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Tutorial/WelcometotheSplunktutorial&lt;/A&gt;&lt;BR /&gt;
Exploring Splunk: &lt;A href="http://www.splunk.com/goto/book"&gt;http://www.splunk.com/goto/book&lt;/A&gt; a really good read.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jan 2013 16:57:10 GMT</pubDate>
    <dc:creator>DaveSavage</dc:creator>
    <dc:date>2013-01-09T16:57:10Z</dc:date>
    <item>
      <title>formatted CDR files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82305#M20904</link>
      <description>&lt;P&gt;Hi &lt;BR /&gt;
 I am very new to Splunk but have been asked to look into the possibility to using Splunk to replace an existing system used query our CDR files.&lt;/P&gt;

&lt;P&gt;From what I can tell Splunk has most of what we would need. &lt;BR /&gt;
The one thing I cannot seem to find is:&lt;BR /&gt;
Our files are comma separated but follow a pattern similar to  ANumber,BNumber,deliveryDate,etc.&lt;BR /&gt;
Our searches would be :&lt;BR /&gt;
return all files where ANumber = ? and BNumber = ? and deliveryDate &amp;gt; ? etc&lt;/P&gt;

&lt;P&gt;Our current system collects the files and inserts them into a database. It is told which field is what and creates a column based on this. The querys are then created to match the columns. &lt;/P&gt;

&lt;P&gt;I cannot see a way of collecting files in Splunk where you can index the files by telling it a format field1,field2 etc&lt;/P&gt;

&lt;P&gt;I hope this all makes sense. I am sure there is a way but that I am unable to see it. &lt;/P&gt;

&lt;P&gt;Thanking you in advance&lt;BR /&gt;
Mary &lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 16:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82305#M20904</guid>
      <dc:creator>MaryCampbell</dc:creator>
      <dc:date>2013-01-09T16:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: formatted CDR files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82306#M20905</link>
      <description>&lt;P&gt;Mary - the good news is that this is possible. You would probably split the fields out (even using the GUI) to create a Regex, defining the field. Searches are easily constructed for ANumber etc.&lt;BR /&gt;
If volume isn't going to cause you a problem with your license (CDRs are big, I know) then you could index the lot. Defining a new index would be advisable.&lt;BR /&gt;
For Regex I'll post the links, ditto the tutorial if they are useful?&lt;BR /&gt;
Br&lt;BR /&gt;
D&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 16:52:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82306#M20905</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2013-01-09T16:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: formatted CDR files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82307#M20906</link>
      <description>&lt;P&gt;Splunk tutorial: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Tutorial/WelcometotheSplunktutorial"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Tutorial/WelcometotheSplunktutorial&lt;/A&gt;&lt;BR /&gt;
Exploring Splunk: &lt;A href="http://www.splunk.com/goto/book"&gt;http://www.splunk.com/goto/book&lt;/A&gt; a really good read.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 16:57:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82307#M20906</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2013-01-09T16:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: formatted CDR files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82308#M20907</link>
      <description>&lt;P&gt;...and this is unmissable &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;
&lt;A href="http://www.youtube.com/watch?v=Yf5gTNiotnM"&gt;http://www.youtube.com/watch?v=Yf5gTNiotnM&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 16:59:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82308#M20907</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2013-01-09T16:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: formatted CDR files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82309#M20908</link>
      <description>&lt;P&gt;What system are your CDR files from?   Sideview makes apps for both Cisco CallManager's CDRs and Shoretel CDR.  And if you can send us sample logs we may very well be able to expand into your particular product.  &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;  If you can help us with sample data to get a new app started we will happily grant you a free perpetual license to use the resulting product.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 21:54:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82309#M20908</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2013-01-09T21:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: formatted CDR files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82310#M20909</link>
      <description>&lt;P&gt;To build on Dave's answer:&lt;/P&gt;

&lt;P&gt;Actually, if the fields are comma-separated, there is an even easier way to tell Splunk how to identity them. Assume that you create a sourcetype called CDR for your data.&lt;/P&gt;

&lt;P&gt;In &lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[CDR]
TRANSFORM-ecf1=extract-CDR-fields
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In &lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[extract-CDR-fields]
DELIMS = ","
FIELDS = ANumber,BNumber,deliveryDate,etc.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;These conf files can be put in $SPLUNK_HOME/etc/system/local&lt;/P&gt;

&lt;P&gt;As Dave pointed out, you should create a separate index for your CDR data. I would suggest this:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Create the new index.&lt;/LI&gt;
&lt;LI&gt;Set up the props.conf and transforms.conf files&lt;/LI&gt;
&lt;LI&gt;Upload some sample CDR into the index. Be sure to specify the CDR sourcetype manually (just type it in) and choose your new index. This can all be done from the Splunk GUI.&lt;/LI&gt;
&lt;LI&gt;Play with the data. If it looks wrong, use the &lt;CODE&gt;clean&lt;/CODE&gt; command to clean out your index and try again.&lt;/LI&gt;
&lt;LI&gt;When the data looks right - clean out the index one more time and then start indexing your real data!&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 10 Jan 2013 10:53:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82310#M20909</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-01-10T10:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: formatted CDR files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82311#M20910</link>
      <description>&lt;P&gt;Nicee ;-)...thanks LG&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2013 13:42:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82311#M20910</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2013-01-10T13:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: formatted CDR files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82312#M20911</link>
      <description>&lt;P&gt;I like the sound of that, and concept sideview &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;
@Mary as you are fairly new to this, blitz through the Exploring Splunk (Splunk Query Language) manual then go play with the data. Quite quickly and with only a v small amount of effort you will have top numbers calling, those called, duration etc. Interested in cost, by department?! Next stop, reference a tariff table, extend your searches and pipe the results to graphs and tables. I appreciate that the sound of all this may have you running for the hills...but I suspect not.&lt;BR /&gt;
Myabe Call Loggers are dead. Think of the savings.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2013 13:53:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/formatted-CDR-files/m-p/82312#M20911</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2013-01-10T13:53:18Z</dc:date>
    </item>
  </channel>
</rss>

