Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to remove the currency symbol etc. from a field before indexing?

$
0
0
This is what the data looks like in the source file (.csv). Notice the $156.03 09/26/13, 2013 , 09-Sep , Week-39 , Thu , - , 4 ,, $156.03 ,, $156.03 ,100%, $39.01 ,,0:00, 13 , $12.00 , This is what I have in my `\etc\system\local\props.conf` SEDCMD-makenumeric = s/\$(\d)/\1/g s/(\d)%/\1/g s/\$-//g s/(\d),(\d)/\1\2/g s/\s?,\s?/,/g This is what the data looks like in `raw` mode in data preview (no currency symbol). SEDCMD appears to be working. 09/26/13,2013,09-Sep,Week-39,Thu,- ,4,,156.03,,156.03,100,39.01,,0:00,13,12.00, However, the $ symbol is back in the `List` and `Table` mode in Data Preview 09/26/13,2013,09-Sep,Week-39,Thu,- ,4,,156.03,,156.03,100,39.01,,0:00,13,12.00, Avg _ Cust = $39.01 Conv = 100% DOW = Thu Date = 09/26/13 Hrs Open = 13 Hrs Worked = 0:00 In_Store = $156.03 Month = 09-Sep No Sale = - Sale _ Hr = $12.00 Sales = 4 Sales Amt = $156.03 Wk No = Week-39 Year = 2013 If I go through with the data import, this search results in the field with $ symbol index=* | table "Sales Amt" Question: How do I get rid of the currency symbol (& other string characters) so a number can be stored as a numeric value when indexed?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>