Splunk Search

case sensitive dedup?

blee_i365
Explorer

I have two hosts, one named lower case 'server01', the other named upper case 'SERVER01'. When I do a search such as "foo | dedup host", I only get either server01 or SERVER01, and never both, because apparently dedup is performing case insensitive comparisons. Is there a way to enable case sensitivity?

Thanks much in Advance.

0 Karma
1 Solution

RyanAdams
Engager

Generally (from a networking perspective) you shouldn't have two hosts with the same hostname. However, since you do, you could use regex to determine if the hostname is upper or lowercase. For example:

... | rex field=host "(?P<upperHost>[A-Z0-9]+)"| eval hostCase=if(isnotnull(upperHost), "Upper", "Lower")

Then you could run the dedup command against both the host name and the value of hostCase:

... | dedup host, hostCase

That should leave both hostnames in the results.

PS: I havn't been able to test this so the isnotnull() may not work. Instead you may want to use upperHost="".

View solution in original post

0 Karma

TobiasBoone
Communicator

dedup really needs to have an in-case sensitivity option

RyanAdams
Engager

Generally (from a networking perspective) you shouldn't have two hosts with the same hostname. However, since you do, you could use regex to determine if the hostname is upper or lowercase. For example:

... | rex field=host "(?P<upperHost>[A-Z0-9]+)"| eval hostCase=if(isnotnull(upperHost), "Upper", "Lower")

Then you could run the dedup command against both the host name and the value of hostCase:

... | dedup host, hostCase

That should leave both hostnames in the results.

PS: I havn't been able to test this so the isnotnull() may not work. Instead you may want to use upperHost="".

0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...