Splunk Search
Highlighted

Compare case-sensitivity of fields

Communicator

I'm using a rex to extract a field called field1 from my search... how do I take all the results of field1 and call out if they match on case or not? ie

_time   abc_123  
_time   ABC_123

_time   def_123
_time   def_123

first example I'd want to say there's a case diff while the second example is fine since the case's match

0 Karma
Highlighted

Re: Compare case-sensitivity of fields

Ultra Champion
0 Karma
Highlighted

Re: Compare case-sensitivity of fields

Communicator

sorry not the regex - I already got the field reguardless of case but now I need to compare them ....

0 Karma
Highlighted

Re: Compare case-sensitivity of fields

Esteemed Legend

The easiest thing is to do this:

... | eval field1lower=lower(field1)
| stats values(field1) values(field1lower) dc(field1) dc(field1lower)

You can also use the ignore-case modifier (?i) for any RegEx.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.