<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk email query subject filter in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632729#M14815</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254197"&gt;@sulaimancds&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you want to exclede events containing keywords from the lookup, you have only to add a NOT condition tto the main search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=mail NOT [ | inputlookup suspicoussubject_keywords | rename keyword AS query | fields query ]
| lookup email_domain_whitelist domain AS RecipientDomain output domain as domain_match 
| where isnull(domain_match) 
| lookup all_email_provider_domains domain AS RecipientDomain output domain as domain_match2 
| where isnotnull(domain_match2) 
| stats values(recipient) as recipient values(subject) as subject earliest(_time) AS "Earliest" latest(_time) AS "Latest" by RecipientDomain sender 
| where mvcount(recipient)=1
| eval subject_count=mvcount(subject)
| sort - subject_count 
| convert ctime("Latest") 
| convert ctime("Earliest")&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 01 Mar 2023 08:33:12 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-03-01T08:33:12Z</dc:date>
    <item>
      <title>Writing a Splunk search to filter email subjects?</title>
      <link>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632701#M14809</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;index=mail 
| lookup email_domain_whitelist domain AS RecipientDomain output domain as domain_match 
| where isnull(domain_match) 
| lookup all_email_provider_domains domain AS RecipientDomain output domain as domain_match2 
| where isnotnull(domain_match2) 
| stats values(recipient) as recipient values(subject) as subject earliest(_time) AS "Earliest" latest(_time) AS "Latest" by RecipientDomain sender 
| where mvcount(recipient)=1
| eval subject_count=mvcount(subject)
| sort - subject_count 
| convert ctime("Latest") 
| convert ctime("Earliest")&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have list of suspicious keywords to in a list in lookup editor called suspicoussubject_keywords.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you include the query to lookup for this keyword in subject and then display results?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in another use case , i have a list not to show the following subject&amp;nbsp; filtersubjects&amp;nbsp; in lookup.&lt;/P&gt;
&lt;P&gt;This will not display the results where there are the following words like CV, Resume in the subjects&lt;/P&gt;
&lt;P&gt;can you help me with the query ?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 14:59:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632701#M14809</guid>
      <dc:creator>sulaimancds</dc:creator>
      <dc:date>2023-03-01T14:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: splunk email query subject filter</title>
      <link>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632721#M14810</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254197"&gt;@sulaimancds&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you have a list of suspicious keywords in a lookup you could add to the main search this condition (assuming that the field in the lookup is called "keyword"):&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=mail [ | inputlookup suspicoussubject_keywords | rename keyword AS query | fields query ]
| ...&lt;/LI-CODE&gt;&lt;P&gt;in this way you performa a full text search on your raw data using the keywords from the lookup.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 08:03:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632721#M14810</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-01T08:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: splunk email query subject filter</title>
      <link>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632722#M14811</link>
      <description>&lt;P&gt;thank you, can you put those into my query as shown above.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 08:06:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632722#M14811</guid>
      <dc:creator>sulaimancds</dc:creator>
      <dc:date>2023-03-01T08:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: splunk email query subject filter</title>
      <link>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632723#M14812</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254197"&gt;@sulaimancds&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;ok, try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=mail [ | inputlookup suspicoussubject_keywords | rename keyword AS query | fields query ]
| lookup email_domain_whitelist domain AS RecipientDomain output domain as domain_match 
| where isnull(domain_match) 
| lookup all_email_provider_domains domain AS RecipientDomain output domain as domain_match2 
| where isnotnull(domain_match2) 
| stats values(recipient) as recipient values(subject) as subject earliest(_time) AS "Earliest" latest(_time) AS "Latest" by RecipientDomain sender 
| where mvcount(recipient)=1
| eval subject_count=mvcount(subject)
| sort - subject_count 
| convert ctime("Latest") 
| convert ctime("Earliest")&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 08:08:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632723#M14812</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-01T08:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: splunk email query subject filter</title>
      <link>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632725#M14813</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;list is saved already.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this error is being showed.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;[subsearch]: The lookup table 'email_subjects' requires a .csv or KV store lookup definition.&lt;/LI&gt;&lt;LI&gt;[subsearch]: The lookup table 'email_subjects' is invalid.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;help.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 08:24:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632725#M14813</guid>
      <dc:creator>sulaimancds</dc:creator>
      <dc:date>2023-03-01T08:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: splunk email query subject filter</title>
      <link>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632728#M14814</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;i have a list not to show the following subject&amp;nbsp; filtersubjects&amp;nbsp; in lookup.&lt;/P&gt;&lt;P&gt;This will not display the results where there are the following words like CV, Resume in the subjects&lt;/P&gt;&lt;P&gt;can you help me with the query ?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 08:25:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632728#M14814</guid>
      <dc:creator>sulaimancds</dc:creator>
      <dc:date>2023-03-01T08:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: splunk email query subject filter</title>
      <link>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632729#M14815</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254197"&gt;@sulaimancds&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you want to exclede events containing keywords from the lookup, you have only to add a NOT condition tto the main search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=mail NOT [ | inputlookup suspicoussubject_keywords | rename keyword AS query | fields query ]
| lookup email_domain_whitelist domain AS RecipientDomain output domain as domain_match 
| where isnull(domain_match) 
| lookup all_email_provider_domains domain AS RecipientDomain output domain as domain_match2 
| where isnotnull(domain_match2) 
| stats values(recipient) as recipient values(subject) as subject earliest(_time) AS "Earliest" latest(_time) AS "Latest" by RecipientDomain sender 
| where mvcount(recipient)=1
| eval subject_count=mvcount(subject)
| sort - subject_count 
| convert ctime("Latest") 
| convert ctime("Earliest")&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 08:33:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632729#M14815</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-01T08:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: splunk email query subject filter</title>
      <link>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632730#M14816</link>
      <description>&lt;P&gt;suspicoussubject_keywords.csv&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;keyword&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;cv&lt;BR /&gt;interview&lt;BR /&gt;offboarding&lt;BR /&gt;resume&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 08:50:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632730#M14816</guid>
      <dc:creator>sulaimancds</dc:creator>
      <dc:date>2023-03-01T08:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: splunk email query subject filter</title>
      <link>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632748#M14817</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254197"&gt;@sulaimancds&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;these errors are in the part of the search that you shared, not in the part I updated.&lt;/P&gt;&lt;P&gt;Anyway, check the &lt;SPAN&gt;email_subjects lookup because&amp;nbsp;&lt;/SPAN&gt;there's an error.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 10:31:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Writing-a-Splunk-search-to-filter-email-subjects/m-p/632748#M14817</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-01T10:31:08Z</dc:date>
    </item>
  </channel>
</rss>

