This is problem is primarily a windows problem in that it frequently will ALL-CAPS hostnames but sometimes leave it the way you configured it. You could modify the hostname in Windows to be ALL-CAPS OR you can override the host at index time OR deal with it at search time like this:
index="Event_Logs" host=WindowServer | eval host=upper(host)
Don't forget about the domain problem, too. Here is a good discussion on that and more details, too:
http://answers.splunk.com/answers/28879/host-value-for-windows.html
... View more