<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: lookup field value case sensitivity in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489055#M136620</link>
    <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Syntax:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;lookup [local=&amp;lt;bool&amp;gt;] [update=&amp;lt;bool&amp;gt;] &amp;lt;lookup-table-name&amp;gt; ( &amp;lt;lookup-field&amp;gt; [AS &amp;lt;event-field&amp;gt;] )... [ OUTPUT | OUTPUTNEW (&amp;lt;lookup-destfield&amp;gt; [AS &amp;lt;event-destfield&amp;gt;] )... ]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;CODE&gt;the default setting for the field values is to be case sensitive.&lt;/CODE&gt;&lt;BR /&gt;
What are you talking about?&lt;/P&gt;</description>
    <pubDate>Wed, 29 Apr 2020 23:24:40 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2020-04-29T23:24:40Z</dc:date>
    <item>
      <title>lookup field value case sensitivity</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489054#M136619</link>
      <description>&lt;P&gt;While field values are &lt;STRONG&gt;not&lt;/STRONG&gt; case sensitive by default on Splunk, when we use lookups the default setting for the field values is to be case sensitive. &lt;/P&gt;

&lt;P&gt;I can't think of any valid use case of that inconsistency, is there any reason that I could possibly be missing? &lt;/P&gt;

&lt;P&gt;note: I am aware that you can overwritte the case sensitivity setting when importing a lookup, I am merely wondering why doen't the default option for lookup field values align with the overall Splunk logic of field values being non case sensitive. &lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 14:59:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489054#M136619</guid>
      <dc:creator>constantinetamp</dc:creator>
      <dc:date>2020-04-29T14:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: lookup field value case sensitivity</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489055#M136620</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Syntax:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;lookup [local=&amp;lt;bool&amp;gt;] [update=&amp;lt;bool&amp;gt;] &amp;lt;lookup-table-name&amp;gt; ( &amp;lt;lookup-field&amp;gt; [AS &amp;lt;event-field&amp;gt;] )... [ OUTPUT | OUTPUTNEW (&amp;lt;lookup-destfield&amp;gt; [AS &amp;lt;event-destfield&amp;gt;] )... ]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;CODE&gt;the default setting for the field values is to be case sensitive.&lt;/CODE&gt;&lt;BR /&gt;
What are you talking about?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 23:24:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489055#M136620</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-04-29T23:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: lookup field value case sensitivity</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489056#M136621</link>
      <description>&lt;P&gt;well what you pasted above is exactly the same thing as I'm stating on my question.&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2020 09:42:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489056#M136621</guid>
      <dc:creator>constantinetamp</dc:creator>
      <dc:date>2020-05-01T09:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: lookup field value case sensitivity</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489057#M136622</link>
      <description>&lt;P&gt;&lt;CODE&gt;lookup&lt;/CODE&gt; arguments are &lt;CODE&gt;fieldname&lt;/CODE&gt; , not &lt;CODE&gt;fieldvalue&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Splexicon:Field"&gt;https://docs.splunk.com/Splexicon:Field&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;and &lt;CODE&gt;lookup&lt;/CODE&gt; is not &lt;CODE&gt;search&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/658367/splunk-eval-case-statement-compare-the-case-sensit.html"&gt;https://answers.splunk.com/answers/658367/splunk-eval-case-statement-compare-the-case-sensit.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2020 09:56:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489057#M136622</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-01T09:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: lookup field value case sensitivity</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489058#M136623</link>
      <description>&lt;P&gt;I'm talking about the field values in lookups being case sensitive, the terms fieldname and fieldvalue in the lookup command that you're referring to are irrelevant to my question &lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2020 12:19:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489058#M136623</guid>
      <dc:creator>constantinetamp</dc:creator>
      <dc:date>2020-05-01T12:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: lookup field value case sensitivity</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489059#M136624</link>
      <description>&lt;P&gt;&lt;CODE&gt;While field values are not case sensitive by default on Splunk&lt;/CODE&gt;&lt;BR /&gt;
this is wrong assumption.&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2020 13:49:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489059#M136624</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-01T13:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: lookup field value case sensitivity</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489060#M136625</link>
      <description>&lt;P&gt;It clearly isn't an assumption that field values are case insentivite and that field names are case sensitive on Splunk, that's clearly stated on the official Splunk documentation, and it's definitely not a wrong one: &lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/65/are-field-values-case-sensitive.html"&gt;https://answers.splunk.com/answers/65/are-field-values-case-sensitive.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2020 15:03:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-field-value-case-sensitivity/m-p/489060#M136625</guid>
      <dc:creator>constantinetamp</dc:creator>
      <dc:date>2020-05-01T15:03:36Z</dc:date>
    </item>
  </channel>
</rss>

