My voip logs have a format of xxxxxxxxxx 10 digit number.
Two questions:
How do I assign a field name of "area_code" to the first 3 digits of the number?
How do I do a geolocate on the area_code?
Thanks in advance for your help
For first one you can use calculated fields.
http://docs.splunk.com/Documentation/Splunk/6.1.2/Knowledge/definecalcfields
May be this one for the second
For first one you can use calculated fields.
http://docs.splunk.com/Documentation/Splunk/6.1.2/Knowledge/definecalcfields
May be this one for the second