Splunk Search

Splunk Case-Sensitive Search

alexspunkshell
Contributor

Hi,

Can someone help me with the regex command for below?

| search ="UPN=*[email protected]"

Thanks in advance!

 

Labels (2)
0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

To validate your ask: You are currently getting both email addresses that end in lowercase and uppercase 'T', because of the default case-insensitivity of search. You need help figuring out how to only return email addresses that have an uppercase 'T' before the '@mail.cloud'.

Is that what you are really asking?

If so, use the CASE function to interpret your search term exactly as typed: 

| search UPN=CASE(*[email protected])

View solution in original post

aasabatini
Motivator

Hi @alexspunkshell 

Can you specify little bit better your request?

you write this:

| search ="UPN=*[email protected]"

but the search comand don't need the "=" symbol

correct example:

| search UPN="*[email protected]"

 

Ale

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”

alexspunkshell
Contributor

@aasabatini  Thanks for your reply.

Yes I need regex for

| search UPN=*[email protected]

If I apply this in my query then, I am also getting results for UPN= t*@mail.cloud also getting due to case sensitivity.

 

Please help me with regex for

| search UPN=*[email protected]

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

To validate your ask: You are currently getting both email addresses that end in lowercase and uppercase 'T', because of the default case-insensitivity of search. You need help figuring out how to only return email addresses that have an uppercase 'T' before the '@mail.cloud'.

Is that what you are really asking?

If so, use the CASE function to interpret your search term exactly as typed: 

| search UPN=CASE(*[email protected])
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...