Splunk Search

Splunk Case-Sensitive Search

alexspunkshell
Contributor

Hi,

Can someone help me with the regex command for below?

| search ="UPN=*T@mail.cloud"

Thanks in advance!

 

Labels (2)
0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

To validate your ask: You are currently getting both email addresses that end in lowercase and uppercase 'T', because of the default case-insensitivity of search. You need help figuring out how to only return email addresses that have an uppercase 'T' before the '@mail.cloud'.

Is that what you are really asking?

If so, use the CASE function to interpret your search term exactly as typed: 

| search UPN=CASE(*T@mail.cloud)

View solution in original post

aasabatini
Motivator

Hi @alexspunkshell 

Can you specify little bit better your request?

you write this:

| search ="UPN=*T@mail.cloud"

but the search comand don't need the "=" symbol

correct example:

| search UPN="*T@mail.cloud"

 

Ale

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”

alexspunkshell
Contributor

@aasabatini  Thanks for your reply.

Yes I need regex for

| search UPN=*T@mail.cloud

If I apply this in my query then, I am also getting results for UPN= t*@mail.cloud also getting due to case sensitivity.

 

Please help me with regex for

| search UPN=*T@mail.cloud

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

To validate your ask: You are currently getting both email addresses that end in lowercase and uppercase 'T', because of the default case-insensitivity of search. You need help figuring out how to only return email addresses that have an uppercase 'T' before the '@mail.cloud'.

Is that what you are really asking?

If so, use the CASE function to interpret your search term exactly as typed: 

| search UPN=CASE(*T@mail.cloud)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...