<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Convert string to decimal number in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Convert-string-to-decimal-number/m-p/27919#M5465</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;i have a field extraction where i have values who are like 21,3&lt;/P&gt;

&lt;P&gt;splunk recognizes them as string. but that are temprature data and i like to have tham as decimal numbers so i fan calculate avarage, lines etc.&lt;/P&gt;

&lt;P&gt;how can i convert them? &lt;BR /&gt;
thanks&lt;/P&gt;</description>
    <pubDate>Wed, 08 May 2013 17:41:58 GMT</pubDate>
    <dc:creator>Matthias_BY</dc:creator>
    <dc:date>2013-05-08T17:41:58Z</dc:date>
    <item>
      <title>Convert string to decimal number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-string-to-decimal-number/m-p/27919#M5465</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;i have a field extraction where i have values who are like 21,3&lt;/P&gt;

&lt;P&gt;splunk recognizes them as string. but that are temprature data and i like to have tham as decimal numbers so i fan calculate avarage, lines etc.&lt;/P&gt;

&lt;P&gt;how can i convert them? &lt;BR /&gt;
thanks&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2013 17:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-string-to-decimal-number/m-p/27919#M5465</guid>
      <dc:creator>Matthias_BY</dc:creator>
      <dc:date>2013-05-08T17:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Convert string to decimal number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-string-to-decimal-number/m-p/27920#M5466</link>
      <description>&lt;P&gt;It appears that the number formatting used in your region is different from that used in my region. Here where I am (state of Illinois in USofA), that value would be displayed as 21.3 versus what your region and many others in the world who use "," where we use ".".&lt;/P&gt;

&lt;P&gt;Have you considered the "charset" parameter in the props.conf file? That might allow Splunk to properly recognize this value as a number instead of a string. Check it out at &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.3/Admin/Propsconf"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.3/Admin/Propsconf&lt;/A&gt;. &lt;/P&gt;

&lt;P&gt;Use your browser's search feature to look for either "International" or "charset" to jump right to the info that explains how this works.&lt;/P&gt;

&lt;P&gt;*** NOTE *** For those interested in the different ways that numbers are formatted and what retions use what format, check out this web page:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.codeproject.com/Articles/78175/International-Number-Formats"&gt;http://www.codeproject.com/Articles/78175/International-Number-Formats&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2013 21:02:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-string-to-decimal-number/m-p/27920#M5466</guid>
      <dc:creator>rgcurry</dc:creator>
      <dc:date>2013-05-08T21:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: Convert string to decimal number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-string-to-decimal-number/m-p/27921#M5467</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;thanks for the tips. i have found out that the software which writes the machine data (cumulus from sandysoft) is using the decimal delimeter from the regional settings on windows.&lt;/P&gt;

&lt;P&gt;i reconfigured on this server to use the dot instead of the comma and now i have my data nice. i'm sure it might have been corrected via props and transform with splunk but that one was the fastest and easiest way.&lt;/P&gt;

&lt;P&gt;br&lt;BR /&gt;
matthias&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2013 06:33:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-string-to-decimal-number/m-p/27921#M5467</guid>
      <dc:creator>Matthias_BY</dc:creator>
      <dc:date>2013-05-09T06:33:03Z</dc:date>
    </item>
  </channel>
</rss>

