<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Postfix_logs_format in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Postfix-logs-format/m-p/324532#M93256</link>
    <description>&lt;P&gt;I have sent a mail. And mail server gives me logs like these.&lt;/P&gt;

&lt;P&gt;Feb 27 11:30:11 mail postfix/qmgr[8620]: 24C4C681F19: &lt;STRONG&gt;from=&lt;A href="mailto:kalam@example.com"&gt;kalam@example.com&lt;/A&gt;&lt;/STRONG&gt;, size=8814, nrcpt=1 (queue active)&lt;BR /&gt;
Feb 27 11:30:11 mail postfix/amavis/smtp[50690]: 24C4C681F19: &lt;STRONG&gt;to=&lt;A href="mailto:salam@example.com"&gt;salam@example.com&lt;/A&gt;&lt;/STRONG&gt;, relay=127.0.0.1[127.0.0.1]:10024, delay=2.1, delays=1.2/0.01/0/0.93, dsn=2.0.0, &lt;STRONG&gt;status=sent&lt;/STRONG&gt; (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as F3433681F7C)&lt;/P&gt;

&lt;P&gt;I want to build a search based on the from address, but do stats on the status (separate counts for deffered, sent, reject etc.). Anyway I could make splunk realize these two events are related?&lt;/P&gt;</description>
    <pubDate>Wed, 28 Feb 2018 04:46:36 GMT</pubDate>
    <dc:creator>abusayeed</dc:creator>
    <dc:date>2018-02-28T04:46:36Z</dc:date>
    <item>
      <title>Postfix_logs_format</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Postfix-logs-format/m-p/324532#M93256</link>
      <description>&lt;P&gt;I have sent a mail. And mail server gives me logs like these.&lt;/P&gt;

&lt;P&gt;Feb 27 11:30:11 mail postfix/qmgr[8620]: 24C4C681F19: &lt;STRONG&gt;from=&lt;A href="mailto:kalam@example.com"&gt;kalam@example.com&lt;/A&gt;&lt;/STRONG&gt;, size=8814, nrcpt=1 (queue active)&lt;BR /&gt;
Feb 27 11:30:11 mail postfix/amavis/smtp[50690]: 24C4C681F19: &lt;STRONG&gt;to=&lt;A href="mailto:salam@example.com"&gt;salam@example.com&lt;/A&gt;&lt;/STRONG&gt;, relay=127.0.0.1[127.0.0.1]:10024, delay=2.1, delays=1.2/0.01/0/0.93, dsn=2.0.0, &lt;STRONG&gt;status=sent&lt;/STRONG&gt; (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as F3433681F7C)&lt;/P&gt;

&lt;P&gt;I want to build a search based on the from address, but do stats on the status (separate counts for deffered, sent, reject etc.). Anyway I could make splunk realize these two events are related?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 04:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Postfix-logs-format/m-p/324532#M93256</guid>
      <dc:creator>abusayeed</dc:creator>
      <dc:date>2018-02-28T04:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Postfix_logs_format</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Postfix-logs-format/m-p/324533#M93257</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;This is answer will help you:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/40922/postfix-logs.html"&gt;https://answers.splunk.com/answers/40922/postfix-logs.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 10:24:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Postfix-logs-format/m-p/324533#M93257</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-03-01T10:24:22Z</dc:date>
    </item>
  </channel>
</rss>

