Splunk Search

Field values are case insensitive?

vn_g
Path Finder

index="win*" host="abc" -- doesnt give results

index="win*" host="ABC" -- gives results

But , it is not suppose to function that way , since I heard Field values are case insensitive? Kindly help

Labels (1)
0 Karma

nickhills
Ultra Champion

Field values in search are not case sensitive

However some other commands like statssort  do utilise case sensitivity.
Also by default, lookups are also case sensitive (although this is configurable)

I can not offer an explanation of why the two very simple examples above would produce different results. Are you able to provide a screenshot demonstrating this?

Are you testing with simple queries (like the example) or is this behaviour observed as part of a larger query?

If my comment helps, please give it a thumbs up!
0 Karma

vn_g
Path Finder

I have attached the screenshot. I am using the simple query which has only index and host name. The hostname is in the format -- AAAAAANNNNNA.

Tags (1)
0 Karma

vn_g
Path Finder

Yes , I am just using the basic search query index and host value .

0 Karma

nickhills
Ultra Champion

What is the format of the hostname?

I can see it's euraXXXXXXXX can you give a full example like this:

eura0-y34-abc3
AAAAN-ANN-AAAN

Where A is a letter, N is a Number and any other character is shown

 

 

If my comment helps, please give it a thumbs up!
0 Karma

vn_g
Path Finder

It is like AAAAAANNNNNA

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...