Hello,
In our Splunk Enterprise, we have created a customized indexer. We are trying to get certain events of a specific host, but as soon as we type index="Event_Logs" host=WindowServer in Search, we get the results of 2 hosts with the same host name.
1. WINDOWSERVER (UPPER_CASE)
2. windowserver (lower_case)
The count appearing in the Search results is different.
Any idea about this behavior?
Appreciate your help.
== Umang Solanki
... View more