I'm using a rex to extract a field called field1 from my search... how do I take all the results of field1 and call out if they match on case or not? ie
_time abc_123
_time ABC_123
_time def_123
_time def_123
first example I'd want to say there's a case diff while the second example is fine since the case's match
The easiest thing is to do this:
... | eval field1lower=lower(field1)
| stats values(field1) values(field1lower) dc(field1) dc(field1lower)
You can also use the ignore-case
modifier (?i)
for any RegEx
.
try (?i)
option
https://www.pcre.org/original/doc/html/pcrepattern.html#SEC13
sorry not the regex - I already got the field reguardless of case but now I need to compare them ....