Splunk Search

Field values are case insensitive?

vn_g
Path Finder

index="win*" host="abc" -- doesnt give results

index="win*" host="ABC" -- gives results

But , it is not suppose to function that way , since I heard Field values are case insensitive? Kindly help

Labels (1)
0 Karma

nickhills
Ultra Champion

Field values in search are not case sensitive

However some other commands like stats, sort  do utilise case sensitivity.
Also by default, lookups are also case sensitive (although this is configurable)

I can not offer an explanation of why the two very simple examples above would produce different results. Are you able to provide a screenshot demonstrating this?

Are you testing with simple queries (like the example) or is this behaviour observed as part of a larger query?

If my comment helps, please give it a thumbs up!
0 Karma

vn_g
Path Finder

I have attached the screenshot. I am using the simple query which has only index and host name. The hostname is in the format -- AAAAAANNNNNA.

Tags (1)
0 Karma

vn_g
Path Finder

Yes , I am just using the basic search query index and host value .

0 Karma

nickhills
Ultra Champion

What is the format of the hostname?

I can see it's euraXXXXXXXX can you give a full example like this:

eura0-y34-abc3
AAAAN-ANN-AAAN

Where A is a letter, N is a Number and any other character is shown

 

 

If my comment helps, please give it a thumbs up!
0 Karma

vn_g
Path Finder

It is like AAAAAANNNNNA

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...