Splunk Search

Splunk Case-Sensitive Search

alexspunkshell
Contributor

Hi,

Can someone help me with the regex command for below?

| search ="UPN=*T@mail.cloud"

Thanks in advance!

 

Labels (2)
0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

To validate your ask: You are currently getting both email addresses that end in lowercase and uppercase 'T', because of the default case-insensitivity of search. You need help figuring out how to only return email addresses that have an uppercase 'T' before the '@mail.cloud'.

Is that what you are really asking?

If so, use the CASE function to interpret your search term exactly as typed: 

| search UPN=CASE(*T@mail.cloud)

View solution in original post

aasabatini
Motivator

Hi @alexspunkshell 

Can you specify little bit better your request?

you write this:

| search ="UPN=*T@mail.cloud"

but the search comand don't need the "=" symbol

correct example:

| search UPN="*T@mail.cloud"

 

Ale

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”

alexspunkshell
Contributor

@aasabatini  Thanks for your reply.

Yes I need regex for

| search UPN=*T@mail.cloud

If I apply this in my query then, I am also getting results for UPN= t*@mail.cloud also getting due to case sensitivity.

 

Please help me with regex for

| search UPN=*T@mail.cloud

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

To validate your ask: You are currently getting both email addresses that end in lowercase and uppercase 'T', because of the default case-insensitivity of search. You need help figuring out how to only return email addresses that have an uppercase 'T' before the '@mail.cloud'.

Is that what you are really asking?

If so, use the CASE function to interpret your search term exactly as typed: 

| search UPN=CASE(*T@mail.cloud)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...