<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manipulating inputs prior search in app in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174742#M50140</link>
    <description>&lt;P&gt;try something like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=yourindex sourcetype=yoursourcetype [|gentimes start=-1 | eval msisdn="10 digit msisdn input" | eval msisdn="999".ltrim(msisdn,"0") | fields msisdn] |table _time, msisdn, sms
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 07 Aug 2014 16:15:04 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-08-07T16:15:04Z</dc:date>
    <item>
      <title>Manipulating inputs prior search in app</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174738#M50136</link>
      <description>&lt;P&gt;I have created an app which has a single input for MSISDN.&lt;/P&gt;

&lt;P&gt;The user enters the MSISDN in local 10-digit format ex: 0123456789&lt;BR /&gt;&lt;BR /&gt;
The events in my logs are in international format ex: 999123456789&lt;/P&gt;

&lt;P&gt;So I need to remove the leading 0 and add 999 to the input prior conducting the search.&lt;BR /&gt;
I have no idea how to do this so all help is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2014 15:40:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174738#M50136</guid>
      <dc:creator>carljohan</dc:creator>
      <dc:date>2014-08-07T15:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulating inputs prior search in app</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174739#M50137</link>
      <description>&lt;P&gt;How are you using the input in  your search? You can use 'ltrim' command with EVAL to trim the leading 0's and prefix '999'.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2014 15:58:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174739#M50137</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-07T15:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulating inputs prior search in app</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174740#M50138</link>
      <description>&lt;P&gt;I have tried the following but it did not work: &lt;BR /&gt;
msisdn="0123456789"| eval msisdn=substr(msisdn,2)|eval msisdn="999".msisdn|table _time, msisdn, sms&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2014 16:08:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174740#M50138</guid>
      <dc:creator>carljohan</dc:creator>
      <dc:date>2014-08-07T16:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulating inputs prior search in app</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174741#M50139</link>
      <description>&lt;P&gt;Give rex a shot: | rex mode=sed field=MSISDN "s/(^0)/999/g"&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2014 16:12:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174741#M50139</guid>
      <dc:creator>aaronkorn</dc:creator>
      <dc:date>2014-08-07T16:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulating inputs prior search in app</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174742#M50140</link>
      <description>&lt;P&gt;try something like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=yourindex sourcetype=yoursourcetype [|gentimes start=-1 | eval msisdn="10 digit msisdn input" | eval msisdn="999".ltrim(msisdn,"0") | fields msisdn] |table _time, msisdn, sms
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 07 Aug 2014 16:15:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174742#M50140</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-07T16:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulating inputs prior search in app</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174743#M50141</link>
      <description>&lt;P&gt;Where in the following search query should I add the regex? &lt;/P&gt;

&lt;P&gt;index=* event="*" msisdn="$customer_msisdn$" |table _time, msisdn, sms&lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2014 13:20:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174743#M50141</guid>
      <dc:creator>carljohan</dc:creator>
      <dc:date>2014-08-12T13:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulating inputs prior search in app</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174744#M50142</link>
      <description>&lt;P&gt;I am not getting it to work. Can I share something which would display the outcome and help you understand why?&lt;/P&gt;

&lt;P&gt;This is the search I am performing: &lt;/P&gt;

&lt;P&gt;index=* sourcetype=sms [|gentimes start=-1 | eval msisdn="0763206619" | eval msisdn="999".ltrim(msisdn,"0") | fields msisdn] |table _time, msisdn, sms&lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2014 13:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174744#M50142</guid>
      <dc:creator>carljohan</dc:creator>
      <dc:date>2014-08-12T13:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulating inputs prior search in app</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174745#M50143</link>
      <description>&lt;P&gt;Here is another find of mine:&lt;/P&gt;

&lt;P&gt;This does not work: index=* sourcetype=sms [|gentimes start=-1 | eval msisdn="0763206619" | eval msisdn="999".ltrim(msisdn,"0") | fields msisdn] |table _time, msisdn, sms&lt;/P&gt;

&lt;P&gt;This does not work: index=* sourcetype=sms [|gentimes start=-1 | eval msisdn="k763206619" | eval msisdn="999".ltrim(msisdn,"k") | fields msisdn] |table _time, msisdn, sms&lt;/P&gt;

&lt;P&gt;This works: index=* sourcetype=sms [|gentimes start=-1 | eval msisdn="k763206619" | eval msisdn="0".ltrim(msisdn,"k") | fields msisdn] |table _time, msisdn, sms&lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2014 14:07:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174745#M50143</guid>
      <dc:creator>carljohan</dc:creator>
      <dc:date>2014-08-12T14:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulating inputs prior search in app</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174746#M50144</link>
      <description>&lt;P&gt;Are you using a textbox for users to enter the msisdn and that input you want to updated before using in the search OR the msisdn is there in the logs with 0763206619 format and you want to update it??&lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2014 17:12:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174746#M50144</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-12T17:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulating inputs prior search in app</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174747#M50145</link>
      <description>&lt;P&gt;Also, can you try something like this?&lt;/P&gt;

&lt;P&gt;index=* sourcetype=sms [|gentimes start=-1 | eval msisdn="0763206619" | eval msisdn="999".ltrim(tostring(msisdn),"0") | fields msisdn] |table _time, msisdn, sms&lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2014 17:15:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174747#M50145</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-12T17:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulating inputs prior search in app</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174748#M50146</link>
      <description>&lt;P&gt;Yes I am using a textbox. The logs are in 999763206619 format and the input is in 0763206619 format.&lt;/P&gt;

&lt;P&gt;The query you provided works when I try it in a search field but not in my custom app with the textfield input.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2014 09:33:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174748#M50146</guid>
      <dc:creator>carljohan</dc:creator>
      <dc:date>2014-08-15T09:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulating inputs prior search in app</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174749#M50147</link>
      <description>&lt;P&gt;When you use the query in dashboard (and I assume you'll have token defined for textbox, lets say token=msisdn), use like this, so that it'll use the single value passed in textbox)&lt;/P&gt;

&lt;P&gt;index=* sourcetype=sms [|gentimes start=-1 | eval msisdn="$msisdn$" | eval msisdn="999".ltrim(tostring(msisdn),"0") | fields msisdn] |table _time, msisdn, sms&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2014 13:17:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Manipulating-inputs-prior-search-in-app/m-p/174749#M50147</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-15T13:17:42Z</dc:date>
    </item>
  </channel>
</rss>

