Splunk Search

case sensitive dedup?

blee_i365
Explorer

I have two hosts, one named lower case 'server01', the other named upper case 'SERVER01'. When I do a search such as "foo | dedup host", I only get either server01 or SERVER01, and never both, because apparently dedup is performing case insensitive comparisons. Is there a way to enable case sensitivity?

Thanks much in Advance.

0 Karma
1 Solution

RyanAdams
Engager

Generally (from a networking perspective) you shouldn't have two hosts with the same hostname. However, since you do, you could use regex to determine if the hostname is upper or lowercase. For example:

... | rex field=host "(?P<upperHost>[A-Z0-9]+)"| eval hostCase=if(isnotnull(upperHost), "Upper", "Lower")

Then you could run the dedup command against both the host name and the value of hostCase:

... | dedup host, hostCase

That should leave both hostnames in the results.

PS: I havn't been able to test this so the isnotnull() may not work. Instead you may want to use upperHost="".

View solution in original post

0 Karma

TobiasBoone
Communicator

dedup really needs to have an in-case sensitivity option

RyanAdams
Engager

Generally (from a networking perspective) you shouldn't have two hosts with the same hostname. However, since you do, you could use regex to determine if the hostname is upper or lowercase. For example:

... | rex field=host "(?P<upperHost>[A-Z0-9]+)"| eval hostCase=if(isnotnull(upperHost), "Upper", "Lower")

Then you could run the dedup command against both the host name and the value of hostCase:

... | dedup host, hostCase

That should leave both hostnames in the results.

PS: I havn't been able to test this so the isnotnull() may not work. Instead you may want to use upperHost="".

0 Karma
Get Updates on the Splunk Community!

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Tips & Tricks When Using Ingest Actions

Tune in to learn about:Large scale architecture when using Ingest ActionsRegEx performance considerations ...