Splunk Search
Highlighted

Compare case-sensitivity of fields

Communicator

I'm using a rex to extract a field called field1 from my search... how do I take all the results of field1 and call out if they match on case or not? ie

_time   abc_123  
_time   ABC_123

_time   def_123
_time   def_123

first example I'd want to say there's a case diff while the second example is fine since the case's match

0 Karma
Highlighted

Re: Compare case-sensitivity of fields

Ultra Champion
0 Karma
Highlighted

Re: Compare case-sensitivity of fields

Communicator

sorry not the regex - I already got the field reguardless of case but now I need to compare them ....

0 Karma
Highlighted

Re: Compare case-sensitivity of fields

Esteemed Legend

The easiest thing is to do this:

... | eval field1lower=lower(field1)
| stats values(field1) values(field1lower) dc(field1) dc(field1lower)

You can also use the ignore-case modifier (?i) for any RegEx.

0 Karma