<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: case sensitive dedup? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/case-sensitive-dedup/m-p/42962#M10102</link>
    <description>&lt;P&gt;dedup IS case-sensitive.  You can convince yourself but running this search:  &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;| stats count | eval foo="bar" | append [stats count | eval foo="BAR"] | table foo |  dedup foo&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
    <pubDate>Tue, 25 Oct 2011 19:42:15 GMT</pubDate>
    <dc:creator>carasso</dc:creator>
    <dc:date>2011-10-25T19:42:15Z</dc:date>
    <item>
      <title>case sensitive dedup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/case-sensitive-dedup/m-p/42961#M10101</link>
      <description>&lt;P&gt;I have two hosts, one named lower case 'server01', the other named upper case 'SERVER01'. When I do a search such as "foo | dedup host", I only get either server01 or SERVER01, and never both, because apparently dedup is performing case insensitive comparisons. Is there a way to enable case sensitivity?&lt;/P&gt;

&lt;P&gt;Thanks much in Advance.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2011 18:56:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/case-sensitive-dedup/m-p/42961#M10101</guid>
      <dc:creator>blee_i365</dc:creator>
      <dc:date>2011-07-14T18:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: case sensitive dedup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/case-sensitive-dedup/m-p/42962#M10102</link>
      <description>&lt;P&gt;dedup IS case-sensitive.  You can convince yourself but running this search:  &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;| stats count | eval foo="bar" | append [stats count | eval foo="BAR"] | table foo |  dedup foo&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 25 Oct 2011 19:42:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/case-sensitive-dedup/m-p/42962#M10102</guid>
      <dc:creator>carasso</dc:creator>
      <dc:date>2011-10-25T19:42:15Z</dc:date>
    </item>
  </channel>
</rss>

