Splunk Search

How to make a search case-sensitive?

muebel
SplunkTrust
SplunkTrust

How can I make a search case-sensitive? That is to say, I search for the general term "FOO" and want to only match "FOO" in results, and not "foo"

Tags (2)
1 Solution

cyue_splunk
Splunk Employee
Splunk Employee

CASE(foo) will only return events with "foo", but not "FOO" or "Foo".

View solution in original post

jburman123
Explorer

I am using SPLUNK Enterprise 6.1, your suggestion of using | where field="FOO" fails

jburman123
Explorer

I want to perform a simple substring match that is case sensitive; for example find all occurrences of Test in a text file and ignore strings like test or test*. If you try CASE(Test) it fails? Any suggestions?

Nikita_Danilov
Path Finder

What Splunk's version are you using? Try it:

| where field="FOO"

cyue_splunk
Splunk Employee
Splunk Employee

CASE(foo) will only return events with "foo", but not "FOO" or "Foo".

northben
Explorer

and in a strange irony, the CASE command is case-sensitive

bwooden
Splunk Employee
Splunk Employee

If the field is extracted: http://answers.splunk.com/questions/3485/can-i-make-field-values-case-sensitive

That thread also contains another technique if the field is not extracted.

ftk
Motivator

Hmm, I don't think you can turn case sensitivity on in the general search, but you should be able to hack it with rex:

foo | rex "(?<uppercase>FOO)" | search uppercase=*
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI &#43; Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...