Hi, I'm working with log data which contains MSISDNs (mobile numbers), which are in the form of "491701234567". It's a CSV-style flatfile log format I'm using.
Doing a search
msisdn=491701234567
does not work (double-quoting also doesn't help). Strangely, using "491701234567" without field name works, but I need field name matches.
Apparently, Splunk stores the MSISDNs in some kind of numerical format where mantissa precision loss is an issue. But MSISDNs are not numbers, they are basically strings with a numerical alphabet (you can't do sensible numerical operations with MSISDNs).
How do I get Splunk to store them in a string field type despite of digit-only content?
Thanks,
Stefan
... View more