Skip to content

Conversation

@ljstella
Copy link
Contributor

So, casing is weird. Search is generally case insensitive for fields (like sourcetype)- but field extraction based on the sourcetype is not necessarily case insensitive. The real example case here for this is xmlwineventlog vs XmlWinEventlog (or event xMlWiNeVeNtLoG if you want to cause pain) - the extractions applied to each one could be different, depending on the version of Splunk, the version of the TA, etc. But generally these are "equivalent-ish". Rather than tell customers that their data of xmlwineventlog doesn't satisfy XmlWinEventLog, we should probably hope they know their data isn't broken to a considerable degree.

See TR-4187.

@ljstella ljstella requested a review from pyth0n1c July 10, 2025 21:11
@ljstella ljstella self-assigned this Jul 10, 2025
Copy link
Contributor

@pyth0n1c pyth0n1c left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Based on included discussion and ticket, I agree that this is correct. Thanks for the additional context and feedback team!

@pyth0n1c pyth0n1c merged commit 3a5e654 into main Jul 30, 2025
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants