Splunk ITSI

Is SPlunk Query casesensitive ?

vickyjaiswal
New Member

Hi Guys,

As I am novice to Splunk .Only I want to know is splunk case sensitive or not .Sometimes my search is work with same query some times it does not work .

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

SPL is case sensitive except for values in the search command. Example:

host="foo" | stats dc(A) by b

host, A, b is case sensitive, "foo" is not.

0 Karma

riddhichandaran
Explorer

Field values are not case sensitive
Field names are always case sensitive, in the search command and in other commands.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...