Hi,
Sorry noob with splunk and I have a problem, not sure where to start but looking for some hints or tips.
Problem: I am extracting CDR (Call Detail Records) from my VoIP system into splunk. I have a field in the extraction called id_dialed_num that contains the dial string the station dialled. I'm looking to chart this field into a pie chart under three categories;
Any ideas where to start?
Thanks
Hello Rapidmobstar,
You can easily do that using an eval/ case expression.
Your search should look something like that:
*your search* | eval Type= "International Number" | eval Type=case(match(PHONENUMBER,"^07*"),"Mobile Number",
match(PHONENUMBER,"^0[1-6]|[8-9]*"),"Local Number") | stats count by Type
Adding this eval to your search will first set the field "Type" to international for all your numbers. Then in case the number starts with 07 will change the Type to Mobile Number. And in case it is a local number it will set the type to local (Local number is starts with 0 then something [1-6] or [8-9] )
Regards,
David
Hello Rapidmobstar,
You can easily do that using an eval/ case expression.
Your search should look something like that:
*your search* | eval Type= "International Number" | eval Type=case(match(PHONENUMBER,"^07*"),"Mobile Number",
match(PHONENUMBER,"^0[1-6]|[8-9]*"),"Local Number") | stats count by Type
Adding this eval to your search will first set the field "Type" to international for all your numbers. Then in case the number starts with 07 will change the Type to Mobile Number. And in case it is a local number it will set the type to local (Local number is starts with 0 then something [1-6] or [8-9] )
Regards,
David