Splunk Search

lookup field value case sensitivity

constantinetamp
Observer

While field values are not case sensitive by default on Splunk, when we use lookups the default setting for the field values is to be case sensitive.

I can't think of any valid use case of that inconsistency, is there any reason that I could possibly be missing?

note: I am aware that you can overwritte the case sensitivity setting when importing a lookup, I am merely wondering why doen't the default option for lookup field values align with the overall Splunk logic of field values being non case sensitive.

0 Karma

to4kawa
Ultra Champion

https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup

Syntax:

lookup [local=<bool>] [update=<bool>] <lookup-table-name> ( <lookup-field> [AS <event-field>] )... [ OUTPUT | OUTPUTNEW (<lookup-destfield> [AS <event-destfield>] )... ]

the default setting for the field values is to be case sensitive.
What are you talking about?

0 Karma

constantinetamp
Observer

well what you pasted above is exactly the same thing as I'm stating on my question.

0 Karma

to4kawa
Ultra Champion
0 Karma

constantinetamp
Observer

I'm talking about the field values in lookups being case sensitive, the terms fieldname and fieldvalue in the lookup command that you're referring to are irrelevant to my question

0 Karma

to4kawa
Ultra Champion

While field values are not case sensitive by default on Splunk
this is wrong assumption.

0 Karma

constantinetamp
Observer

It clearly isn't an assumption that field values are case insentivite and that field names are case sensitive on Splunk, that's clearly stated on the official Splunk documentation, and it's definitely not a wrong one:

https://answers.splunk.com/answers/65/are-field-values-case-sensitive.html

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...