Splunk Search

Field values are case insensitive?

vn_g
Path Finder

index="win*" host="abc" -- doesnt give results

index="win*" host="ABC" -- gives results

But , it is not suppose to function that way , since I heard Field values are case insensitive? Kindly help

Labels (1)
0 Karma

nickhills
Ultra Champion

Field values in search are not case sensitive

However some other commands like statssort  do utilise case sensitivity.
Also by default, lookups are also case sensitive (although this is configurable)

I can not offer an explanation of why the two very simple examples above would produce different results. Are you able to provide a screenshot demonstrating this?

Are you testing with simple queries (like the example) or is this behaviour observed as part of a larger query?

If my comment helps, please give it a thumbs up!
0 Karma

vn_g
Path Finder

I have attached the screenshot. I am using the simple query which has only index and host name. The hostname is in the format -- AAAAAANNNNNA.

Tags (1)
0 Karma

vn_g
Path Finder

Yes , I am just using the basic search query index and host value .

0 Karma

nickhills
Ultra Champion

What is the format of the hostname?

I can see it's euraXXXXXXXX can you give a full example like this:

eura0-y34-abc3
AAAAN-ANN-AAAN

Where A is a letter, N is a Number and any other character is shown

 

 

If my comment helps, please give it a thumbs up!
0 Karma

vn_g
Path Finder

It is like AAAAAANNNNNA

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...