When I put below
sourcetype="splunk_page_search" | top limit=10 keyword
the result..
1 AAA
2 aaa
3 BBB
4 ccc
.
.
.
actually, 1 and 2 are same.
just 1 is capital letters and 2 is small letters.
I want the result below
1 AAA
2 BBB
3 ccc
.
.
.
aaa is disappeared but it is included in AAA.
Is there any good idea?
use eval function to either change your result to uppercase or Lowercase. Try the following search query :
sourcetype="splunk_page_search" | eval keyword=lower(keyword) | top limit=10 keyword
or
sourcetype="splunk_page_search" | eval keyword=upper(keyword) | top limit=10 keyword
I am not sure whether this will work or not. But you can try.
Go through the following splunk Documentation link text
use eval function to either change your result to uppercase or Lowercase. Try the following search query :
sourcetype="splunk_page_search" | eval keyword=lower(keyword) | top limit=10 keyword
or
sourcetype="splunk_page_search" | eval keyword=upper(keyword) | top limit=10 keyword
I am not sure whether this will work or not. But you can try.
Go through the following splunk Documentation link text
Thank you so much!!