<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Co-relation Search between two data sources in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/440486#M142499</link>
    <description>&lt;P&gt;Thanks for the quick turnaround on this. The GUID fields are different in the two data sources: uppercase GUID in Data Source 1, and lowercase guid in Data Source 2. Below is the sample data for both:&lt;/P&gt;

&lt;P&gt;Data Source 1 Sample:&lt;/P&gt;

&lt;P&gt;{"quarantineFolder": "Phish", "recipient": ["&lt;A href="mailto:steve.rogers@company.com" target="_blank"&gt;steve.rogers@company.com&lt;/A&gt;"], "QID": "2sbcak8mm0-1", "sender": "&lt;A href="mailto:3be962b290f7d4a361202d6b52be9e9b@rp.mail-tripactions.com" target="_blank"&gt;3be962b290f7d4a361202d6b52be9e9b@rp.mail-tripactions.com&lt;/A&gt;", "policyRoutes": ["default_inbound"], "eventTime": "2019-05-07T18:42:39.757Z", "messageID": "&amp;lt;1371062311.475.1557254082679.JavaMail.sbx_user1051@169.254.47.69&amp;gt;", "headerFrom": "Tony Stark ", "impostorScore": 0.0, "replyToAddress": ["&lt;A href="mailto:3be962b290f7d4a361202d6b52be9e9b@mail-tripactions.com" target="_blank"&gt;3be962b290f7d4a361202d6b52be9e9b@mail-tripactions.com&lt;/A&gt;"], "ccAddresses": [], "malwareScore": 0, "xmailer": null, "eventType": "messagesBlocked", "messageTime": "2019-05-07T18:35:21.000Z", "completelyRewritten": false, "messageParts": [{"md5": "c139278b3a51a8712063ff19609d411e", "filename": "text.txt", "sha256": "7b021d9fec5568fb3e67e9be9110fac200689436ca463f44e9d7b207d7cf7bed", "sandboxStatus": null, "disposition": "inline", "contentType": "text/plain", "oContentType": "text/plain"}, {"md5": "1e19fa28a8275bd5af6bce235705f492", "filename": "text.html", "sha256": "15878b8a0f8003d0b8503e33ed78175df92e86ca55fb91369d0cf87fe9c7b127", "sandboxStatus": null, "disposition": "inline", "contentType": "text/html", "oContentType": "text/html"}], "phishScore": 100, "modulesRun": ["access", "smtpsrv", "av", "zerohour", "spf", "dkimv", "sandbox", "spam", "dmarc", "pdr", "urldefense"], "subject": "Subject of Email", "toAddresses": ["&lt;A href="mailto:steve.rogers@company.com" target="_blank"&gt;steve.rogers@company.com&lt;/A&gt;"], "quarantineRule": "module.spam.rule.inbound_phish", "GUID": "WMq0EMGv4NCPoZo6V_UK8U-GsC3eZYvC", "fromAddress": ["&lt;A href="mailto:3be962b290f7d4a361202d6b52be9e9b@mail-tripactions.com" target="_blank"&gt;3be962b290f7d4a361202d6b52be9e9b@mail-tripactions.com&lt;/A&gt;"], "cluster": "agrium_hosted", "senderIP": "192.168.111.222", "headerReplyTo": "Tony Stark ", "spamScore": 100, "threatsInfoMap": [{"campaignID": null, "threatStatus": "active", "threatTime": "2019-05-07T16:06:03.000Z", "threat": "mail-tripactions.com", "threatID": "b8f436f2a79eed6bf6877d4081a8d79aa332e835dcc6caeaf20fe6ae3ce0a8fb", "classification": "phish", "threatUrl": "&lt;A href="https://threatinsight.proofpoint.com/43242342dummy-text/threat/email/b8f436f2a79eed6bf6877dummydummyfe6ae3ce0a8fb" target="_blank"&gt;https://threatinsight.proofpoint.com/43242342dummy-text/threat/email/b8f436f2a79eed6bf6877dummydummyfe6ae3ce0a8fb&lt;/A&gt;", "threatType": "url"}], "messageSize": 5670}&lt;/P&gt;

&lt;P&gt;Data Source 2 sample:&lt;/P&gt;

&lt;P&gt;{"guid": "Irhblj4vS9DsfIwHAFbT8pbzf2mZQISa", "msg": {"parsedAddresses": {"to": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;"], "from": ["&lt;A href="mailto:no-reply-sort@cisco.com" target="_blank"&gt;no-reply-sort@cisco.com&lt;/A&gt;"]}, "lang": "en", "sizeBytes": 26337, "normalizedHeader": {"subject": ["[EXT] Subject of email"], "message-id": ["1423317795.5042.1557254884493@brms-prd1-25"], "to": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;, &lt;A href="mailto:supportTT@met-networks.com" target="_blank"&gt;supportTT@met-networks.com&lt;/A&gt;, \&lt;A href="mailto:tsopetrov@cisco.com" target="_blank"&gt;tsopetrov@cisco.com&lt;/A&gt;"], "from": ["SORT - PROD "]}, "header": {"subject": ["Subject of email"], "message-id": ["&lt;A href="mailto:1423317795.5042.1557254884493@brms-prd1-25" target="_blank"&gt;1423317795.5042.1557254884493@brms-prd1-25&lt;/A&gt;"], "to": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;, &lt;A href="mailto:supportTT@met-networks.com" target="_blank"&gt;supportTT@met-networks.com&lt;/A&gt;, \r\n\&lt;A href="mailto:tsopetrov@cisco.com" target="_blank"&gt;tsopetrov@cisco.com&lt;/A&gt;"], "from": ["SORT - PROD "]}}, "action_spf": [{"action": "add-header", "rule": "pass", "module": "spf"}, {"action": "continue", "rule": "pass", "module": "spf"}], "final_rule": "pass", "ts": "2019-05-07T12:48:05.173614-0600", "connection": {"tls": {"inbound": {"cipher": "ECDHE-RSA-AES256-GCM-SHA384", "cipherBits": 256, "version": "TLSv1.2"}}, "helo": "alln-app-2.cisco.com", "country": "us", "sid": "2sbeggg6s0", "protocol": "smtp:smtp", "ip": "173.37.142.87", "resolveStatus": "ok", "host": "alln-app-2.cisco.com"}, "pps": {"cid": "agrium_hosted", "agent": "m0046467.ppops.net", "version": "8.11.10.11"}, "envelope": {"rcpts": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;"], "from": "&lt;A href="mailto:no-reply-sort@cisco.com" target="_blank"&gt;no-reply-sort@cisco.com&lt;/A&gt;"}, "action_dkimv": [], "final_module": "pdr", "action_dmarc": [{"action": "continue", "rule": "pass", "module": "dmarc"}], "msgParts": [{"detectedName": "text.html", "labeledName": "text.html", "textExtracted": "U0NBTEFSKDB4N2YzM2U4MTVjZWE4KQ==\n", "detectedSizeBytes": 17794, "labeledMime": "text/html", "sizeDecodedBytes": 17794, "isVirtual": false, "metadata": {}, "labeledCharset": "UTF-8", "sha256": "5029cc915965d0140e2d0ba88c2ae297c278d3a6c1c8b9c228bf515b8b8ab80c", "md5": "cab46e55f172b2b13f9db709cd3bc4db", "detectedExt": "HTML", "disposition": "inline", "isCorrupted": false, "isDeleted": false, "detectedCharset": "UTF-8", "isArchive": false, "dataBase64": "U0NBTEFSKDB4N2YzM2VmZjE3YTAwKQ==\n", "isProtected": false, "structureId": "0", "urls": [{"src": ["urldefense"], "url": "&lt;A href="https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html&lt;/A&gt;", "isRewritten": true}, {"src": ["urldefense"], "url": "&lt;A href="http://www.cisco.com" target="_blank"&gt;http://www.cisco.com&lt;/A&gt;", "isRewritten": true}, {"src": ["urldefense"], "url": "&lt;A href="https://ibpm.cisco.com/rma/home/?OrderNumber=800127380" target="_blank"&gt;https://ibpm.cisco.com/rma/home/?OrderNumber=800127380&lt;/A&gt;", "isRewritten": true}, {"src": ["urldefense"], "url": "&lt;A href="https://ibpm.cisco.com/rma/home" target="_blank"&gt;https://ibpm.cisco.com/rma/home&lt;/A&gt;", "isRewritten": true}, {"src": ["urldefense"], "url": "&lt;A href="http://supportforums.cisco.com/t5/collaboration-voice-and-video/simplifying-your-cisco-rma-experience/ba-p/3191165" target="_blank"&gt;http://supportforums.cisco.com/t5/collaboration-voice-and-video/simplifying-your-cisco-rma-experience/ba-p/3191165&lt;/A&gt;", "isRewritten": true}], "labeledExt": "html", "isTimedOut": false, "detectedMime": "text/html"}, {"detectedName": "webwb/cisconewlogo.png", "labeledName": "webwb/cisconewlogo.png", "textExtracted": "U0NBTEFSKDB4N2YzM2U4MTAyN2QwKQ==\n", "detectedSizeBytes": 2075, "labeledMime": "image/png", "sizeDecodedBytes": 2075, "isVirtual": false, "metadata": {}, "labeledCharset": "", "sha256": "bb699845aa6f18f0baf339ea3969597abcfdfebb77956efebc5de2d6e1e90c10", "md5": "c6c532f7ebb183c4af68a2d8e320a4ad", "detectedExt": "PNG", "disposition": "attached", "isCorrupted": false, "isDeleted": false, "detectedCharset": "", "isArchive": false, "dataBase64": "U0NBTEFSKDB4N2YzNGRlM2UyMmQ4KQ==\n", "isProtected": false, "structureId": "0", "urls": [], "labeledExt": "png", "isTimedOut": false, "detectedMime": "image/png"}, {"detectedName": "webwb/call_icon.png", "labeledName": "webwb/call_icon.png", "textExtracted": "U0NBTEFSKDB4N2YzM2U4MDE2MzYwKQ==\n", "detectedSizeBytes": 404, "labeledMime": "image/png", "sizeDecodedBytes": 404, "isVirtual": false, "metadata": {}, "labeledCharset": "", "sha256": "d66320e32e99380d33a5cc9212c4216d4ce1c50d34d345b973f4c616a7d7c877", "md5": "dc27600bcf8b5e4cdd882dd4b03eb9ff", "detectedExt": "PNG", "disposition": "attached", "isCorrupted": false, "isDeleted": false, "detectedCharset": "", "isArchive": false, "dataBase64": "U0NBTEFSKDB4N2YzM2U4MTc1NTk4KQ==\n", "isProtected": false, "structureId": "0", "urls": [], "labeledExt": "png", "isTimedOut": false, "detectedMime": "image/png"}], "final_action": "continue", "filter": {"suborgs": {"sender": "0", "rcpts": ["0"]}, "verified": {"rcpts": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;"]}, "qid": "x47IiaKB013302", "quarantine": {"rule": "", "folder": ""}, "modules": {"pdr": {"v2": {"response": "pass"}}, "dkimv": [{"selector": "app", "domain": "cisco.com", "result": "pass"}], "spf": {"domain": "cisco.com", "result": "pass"}, "spam": {"scores": {"classifiers": {"mlx": 0, "impostor": 0, "spam": 0, "adult": 0, "phish": 0, "bulk": 0, "lowpriority": 0, "suspect": 5, "mlxlog": 999, "malware": 0}, "overall": 0}}, "dmarc": {"records": [{"query": "_dmarc.cisco.com", "record": "v=DMARC1; p=quarantine; pct=0; fo=1; ri=3600; rua=mailto:&lt;A href="mailto:cisco@rua.agari.com" target="_blank"&gt;cisco@rua.agari.com&lt;/A&gt;; ruf=mailto:&lt;A href="mailto:cisco@ruf.agari.com" target="_blank"&gt;cisco@ruf.agari.com&lt;/A&gt;"}], "authResults": [{"emailIdentities": {"smtp.mailfrom": "&lt;A href="mailto:no-reply-sort@cisco.com" target="_blank"&gt;no-reply-sort@cisco.com&lt;/A&gt;"}, "result": "pass", "method": "spf"}, {"result": "pass", "propspec": {"header.s": "app", "header.d": "cisco.com"}, "method": "dkim"}, {"emailIdentities": {"header.from": "cisco.com"}, "result": "pass", "method": "dmarc"}], "alignment": [{"from_domain": "cisco.com", "spf": {"identity": "cisco.com", "align": "strict", "identity_org": "cisco.com"}, "dkim": [{"identity": "cisco.com", "align": "strict", "identity_org": "cisco.com"}]}], "srvid": "agrium.com", "filterdResult": "pass"}, "zerohour": {"score": "unknown"}, "urldefense": {"counts": {"unique": 5, "total": 6, "rewritten": 6}, "version": {"engine": "15"}}}, "durationSecs": 0.581787, "routes": ["default_inbound"], "isMsgReinjected": false, "disposition": "continue", "msgSizeBytes": 28953, "isMsgEncrypted": false, "routeDirection": "inbound", "actions": [{"action": "continue", "rule": "pass", "isFinal": true, "module": "pdr"}, {"action": "set-header", "rule": "EXT_add_tag", "module": "access"}, {"action": "continue", "rule": "EXT_add_tag", "module": "access"}, {"action": "add-header", "rule": "pass", "module": "spf"}, {"action": "continue", "rule": "pass", "module": "spf"}, {"action": "add-header", "rule": "clean", "module": "av"}, {"action": "continue", "rule": "clean", "module": "av"}, {"action": "continue", "rule": "pass", "module": "dmarc"}, {"action": "add-header", "rule": "inbound_notspam", "module": "spam"}], "startTime": "2019-05-07T12:48:05.173614-0600"}}&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 00:26:48 GMT</pubDate>
    <dc:creator>swaguzari</dc:creator>
    <dc:date>2020-09-30T00:26:48Z</dc:date>
    <item>
      <title>Co-relation Search between two data sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/440484#M142497</link>
      <description>&lt;P&gt;Mighty Splunk people... I'm having a problem creating an alert for following scenario:&lt;/P&gt;

&lt;P&gt;Data source 1: index=mail sourcetype=proofpoint_tap_siem (interesting fields = GUID)&lt;BR /&gt;
Data source 2: index=mail sourcetype=pps_messagelog (interesting fields = guid, final_action)&lt;/P&gt;

&lt;P&gt;Basically I want a search which would fire up an alert whenever GUID from 1 matches guid from 2 and has final_action=continue.&lt;/P&gt;

&lt;P&gt;Any leads will be much appreciated&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:21:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/440484#M142497</guid>
      <dc:creator>swaguzari</dc:creator>
      <dc:date>2020-09-30T00:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: Co-relation Search between two data sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/440485#M142498</link>
      <description>&lt;P&gt;if you can post some sample data, it would have been great&lt;/P&gt;

&lt;P&gt;But the idea would be something in terms of:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=mail (sourcetype=proofpoint_tap_siem OR sourcetype=pps_messagelog)
|rename guid as GUID
| transaction GUID endswith="final_action=continue" keepevicted=true
| search closed_txn=1
| fields _time,GUID,final_action
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or if you want to be more specific, create a key-value for each sourcetype; something like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=mail (sourcetype=proofpoint_tap_siem OR sourcetype=pps_messagelog)
|rename guid as GUID
| eval start_event=if(sourcetype=proofpoint_tap_siem, "pair1","na")
| eval end_event=if((sourcetype=pps_messagelog) AND (final_action=continue), "pair2","na")
| transaction GUID startswith="start_event=pair1" endswith="end_event=pair2" keepevicted=true
| search closed_txn=1
| fields _time,GUID,final_action
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 06 May 2019 21:17:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/440485#M142498</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2019-05-06T21:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Co-relation Search between two data sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/440486#M142499</link>
      <description>&lt;P&gt;Thanks for the quick turnaround on this. The GUID fields are different in the two data sources: uppercase GUID in Data Source 1, and lowercase guid in Data Source 2. Below is the sample data for both:&lt;/P&gt;

&lt;P&gt;Data Source 1 Sample:&lt;/P&gt;

&lt;P&gt;{"quarantineFolder": "Phish", "recipient": ["&lt;A href="mailto:steve.rogers@company.com" target="_blank"&gt;steve.rogers@company.com&lt;/A&gt;"], "QID": "2sbcak8mm0-1", "sender": "&lt;A href="mailto:3be962b290f7d4a361202d6b52be9e9b@rp.mail-tripactions.com" target="_blank"&gt;3be962b290f7d4a361202d6b52be9e9b@rp.mail-tripactions.com&lt;/A&gt;", "policyRoutes": ["default_inbound"], "eventTime": "2019-05-07T18:42:39.757Z", "messageID": "&amp;lt;1371062311.475.1557254082679.JavaMail.sbx_user1051@169.254.47.69&amp;gt;", "headerFrom": "Tony Stark ", "impostorScore": 0.0, "replyToAddress": ["&lt;A href="mailto:3be962b290f7d4a361202d6b52be9e9b@mail-tripactions.com" target="_blank"&gt;3be962b290f7d4a361202d6b52be9e9b@mail-tripactions.com&lt;/A&gt;"], "ccAddresses": [], "malwareScore": 0, "xmailer": null, "eventType": "messagesBlocked", "messageTime": "2019-05-07T18:35:21.000Z", "completelyRewritten": false, "messageParts": [{"md5": "c139278b3a51a8712063ff19609d411e", "filename": "text.txt", "sha256": "7b021d9fec5568fb3e67e9be9110fac200689436ca463f44e9d7b207d7cf7bed", "sandboxStatus": null, "disposition": "inline", "contentType": "text/plain", "oContentType": "text/plain"}, {"md5": "1e19fa28a8275bd5af6bce235705f492", "filename": "text.html", "sha256": "15878b8a0f8003d0b8503e33ed78175df92e86ca55fb91369d0cf87fe9c7b127", "sandboxStatus": null, "disposition": "inline", "contentType": "text/html", "oContentType": "text/html"}], "phishScore": 100, "modulesRun": ["access", "smtpsrv", "av", "zerohour", "spf", "dkimv", "sandbox", "spam", "dmarc", "pdr", "urldefense"], "subject": "Subject of Email", "toAddresses": ["&lt;A href="mailto:steve.rogers@company.com" target="_blank"&gt;steve.rogers@company.com&lt;/A&gt;"], "quarantineRule": "module.spam.rule.inbound_phish", "GUID": "WMq0EMGv4NCPoZo6V_UK8U-GsC3eZYvC", "fromAddress": ["&lt;A href="mailto:3be962b290f7d4a361202d6b52be9e9b@mail-tripactions.com" target="_blank"&gt;3be962b290f7d4a361202d6b52be9e9b@mail-tripactions.com&lt;/A&gt;"], "cluster": "agrium_hosted", "senderIP": "192.168.111.222", "headerReplyTo": "Tony Stark ", "spamScore": 100, "threatsInfoMap": [{"campaignID": null, "threatStatus": "active", "threatTime": "2019-05-07T16:06:03.000Z", "threat": "mail-tripactions.com", "threatID": "b8f436f2a79eed6bf6877d4081a8d79aa332e835dcc6caeaf20fe6ae3ce0a8fb", "classification": "phish", "threatUrl": "&lt;A href="https://threatinsight.proofpoint.com/43242342dummy-text/threat/email/b8f436f2a79eed6bf6877dummydummyfe6ae3ce0a8fb" target="_blank"&gt;https://threatinsight.proofpoint.com/43242342dummy-text/threat/email/b8f436f2a79eed6bf6877dummydummyfe6ae3ce0a8fb&lt;/A&gt;", "threatType": "url"}], "messageSize": 5670}&lt;/P&gt;

&lt;P&gt;Data Source 2 sample:&lt;/P&gt;

&lt;P&gt;{"guid": "Irhblj4vS9DsfIwHAFbT8pbzf2mZQISa", "msg": {"parsedAddresses": {"to": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;"], "from": ["&lt;A href="mailto:no-reply-sort@cisco.com" target="_blank"&gt;no-reply-sort@cisco.com&lt;/A&gt;"]}, "lang": "en", "sizeBytes": 26337, "normalizedHeader": {"subject": ["[EXT] Subject of email"], "message-id": ["1423317795.5042.1557254884493@brms-prd1-25"], "to": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;, &lt;A href="mailto:supportTT@met-networks.com" target="_blank"&gt;supportTT@met-networks.com&lt;/A&gt;, \&lt;A href="mailto:tsopetrov@cisco.com" target="_blank"&gt;tsopetrov@cisco.com&lt;/A&gt;"], "from": ["SORT - PROD "]}, "header": {"subject": ["Subject of email"], "message-id": ["&lt;A href="mailto:1423317795.5042.1557254884493@brms-prd1-25" target="_blank"&gt;1423317795.5042.1557254884493@brms-prd1-25&lt;/A&gt;"], "to": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;, &lt;A href="mailto:supportTT@met-networks.com" target="_blank"&gt;supportTT@met-networks.com&lt;/A&gt;, \r\n\&lt;A href="mailto:tsopetrov@cisco.com" target="_blank"&gt;tsopetrov@cisco.com&lt;/A&gt;"], "from": ["SORT - PROD "]}}, "action_spf": [{"action": "add-header", "rule": "pass", "module": "spf"}, {"action": "continue", "rule": "pass", "module": "spf"}], "final_rule": "pass", "ts": "2019-05-07T12:48:05.173614-0600", "connection": {"tls": {"inbound": {"cipher": "ECDHE-RSA-AES256-GCM-SHA384", "cipherBits": 256, "version": "TLSv1.2"}}, "helo": "alln-app-2.cisco.com", "country": "us", "sid": "2sbeggg6s0", "protocol": "smtp:smtp", "ip": "173.37.142.87", "resolveStatus": "ok", "host": "alln-app-2.cisco.com"}, "pps": {"cid": "agrium_hosted", "agent": "m0046467.ppops.net", "version": "8.11.10.11"}, "envelope": {"rcpts": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;"], "from": "&lt;A href="mailto:no-reply-sort@cisco.com" target="_blank"&gt;no-reply-sort@cisco.com&lt;/A&gt;"}, "action_dkimv": [], "final_module": "pdr", "action_dmarc": [{"action": "continue", "rule": "pass", "module": "dmarc"}], "msgParts": [{"detectedName": "text.html", "labeledName": "text.html", "textExtracted": "U0NBTEFSKDB4N2YzM2U4MTVjZWE4KQ==\n", "detectedSizeBytes": 17794, "labeledMime": "text/html", "sizeDecodedBytes": 17794, "isVirtual": false, "metadata": {}, "labeledCharset": "UTF-8", "sha256": "5029cc915965d0140e2d0ba88c2ae297c278d3a6c1c8b9c228bf515b8b8ab80c", "md5": "cab46e55f172b2b13f9db709cd3bc4db", "detectedExt": "HTML", "disposition": "inline", "isCorrupted": false, "isDeleted": false, "detectedCharset": "UTF-8", "isArchive": false, "dataBase64": "U0NBTEFSKDB4N2YzM2VmZjE3YTAwKQ==\n", "isProtected": false, "structureId": "0", "urls": [{"src": ["urldefense"], "url": "&lt;A href="https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html&lt;/A&gt;", "isRewritten": true}, {"src": ["urldefense"], "url": "&lt;A href="http://www.cisco.com" target="_blank"&gt;http://www.cisco.com&lt;/A&gt;", "isRewritten": true}, {"src": ["urldefense"], "url": "&lt;A href="https://ibpm.cisco.com/rma/home/?OrderNumber=800127380" target="_blank"&gt;https://ibpm.cisco.com/rma/home/?OrderNumber=800127380&lt;/A&gt;", "isRewritten": true}, {"src": ["urldefense"], "url": "&lt;A href="https://ibpm.cisco.com/rma/home" target="_blank"&gt;https://ibpm.cisco.com/rma/home&lt;/A&gt;", "isRewritten": true}, {"src": ["urldefense"], "url": "&lt;A href="http://supportforums.cisco.com/t5/collaboration-voice-and-video/simplifying-your-cisco-rma-experience/ba-p/3191165" target="_blank"&gt;http://supportforums.cisco.com/t5/collaboration-voice-and-video/simplifying-your-cisco-rma-experience/ba-p/3191165&lt;/A&gt;", "isRewritten": true}], "labeledExt": "html", "isTimedOut": false, "detectedMime": "text/html"}, {"detectedName": "webwb/cisconewlogo.png", "labeledName": "webwb/cisconewlogo.png", "textExtracted": "U0NBTEFSKDB4N2YzM2U4MTAyN2QwKQ==\n", "detectedSizeBytes": 2075, "labeledMime": "image/png", "sizeDecodedBytes": 2075, "isVirtual": false, "metadata": {}, "labeledCharset": "", "sha256": "bb699845aa6f18f0baf339ea3969597abcfdfebb77956efebc5de2d6e1e90c10", "md5": "c6c532f7ebb183c4af68a2d8e320a4ad", "detectedExt": "PNG", "disposition": "attached", "isCorrupted": false, "isDeleted": false, "detectedCharset": "", "isArchive": false, "dataBase64": "U0NBTEFSKDB4N2YzNGRlM2UyMmQ4KQ==\n", "isProtected": false, "structureId": "0", "urls": [], "labeledExt": "png", "isTimedOut": false, "detectedMime": "image/png"}, {"detectedName": "webwb/call_icon.png", "labeledName": "webwb/call_icon.png", "textExtracted": "U0NBTEFSKDB4N2YzM2U4MDE2MzYwKQ==\n", "detectedSizeBytes": 404, "labeledMime": "image/png", "sizeDecodedBytes": 404, "isVirtual": false, "metadata": {}, "labeledCharset": "", "sha256": "d66320e32e99380d33a5cc9212c4216d4ce1c50d34d345b973f4c616a7d7c877", "md5": "dc27600bcf8b5e4cdd882dd4b03eb9ff", "detectedExt": "PNG", "disposition": "attached", "isCorrupted": false, "isDeleted": false, "detectedCharset": "", "isArchive": false, "dataBase64": "U0NBTEFSKDB4N2YzM2U4MTc1NTk4KQ==\n", "isProtected": false, "structureId": "0", "urls": [], "labeledExt": "png", "isTimedOut": false, "detectedMime": "image/png"}], "final_action": "continue", "filter": {"suborgs": {"sender": "0", "rcpts": ["0"]}, "verified": {"rcpts": ["&lt;A href="mailto:bruce.banner@avengers.com" target="_blank"&gt;bruce.banner@avengers.com&lt;/A&gt;"]}, "qid": "x47IiaKB013302", "quarantine": {"rule": "", "folder": ""}, "modules": {"pdr": {"v2": {"response": "pass"}}, "dkimv": [{"selector": "app", "domain": "cisco.com", "result": "pass"}], "spf": {"domain": "cisco.com", "result": "pass"}, "spam": {"scores": {"classifiers": {"mlx": 0, "impostor": 0, "spam": 0, "adult": 0, "phish": 0, "bulk": 0, "lowpriority": 0, "suspect": 5, "mlxlog": 999, "malware": 0}, "overall": 0}}, "dmarc": {"records": [{"query": "_dmarc.cisco.com", "record": "v=DMARC1; p=quarantine; pct=0; fo=1; ri=3600; rua=mailto:&lt;A href="mailto:cisco@rua.agari.com" target="_blank"&gt;cisco@rua.agari.com&lt;/A&gt;; ruf=mailto:&lt;A href="mailto:cisco@ruf.agari.com" target="_blank"&gt;cisco@ruf.agari.com&lt;/A&gt;"}], "authResults": [{"emailIdentities": {"smtp.mailfrom": "&lt;A href="mailto:no-reply-sort@cisco.com" target="_blank"&gt;no-reply-sort@cisco.com&lt;/A&gt;"}, "result": "pass", "method": "spf"}, {"result": "pass", "propspec": {"header.s": "app", "header.d": "cisco.com"}, "method": "dkim"}, {"emailIdentities": {"header.from": "cisco.com"}, "result": "pass", "method": "dmarc"}], "alignment": [{"from_domain": "cisco.com", "spf": {"identity": "cisco.com", "align": "strict", "identity_org": "cisco.com"}, "dkim": [{"identity": "cisco.com", "align": "strict", "identity_org": "cisco.com"}]}], "srvid": "agrium.com", "filterdResult": "pass"}, "zerohour": {"score": "unknown"}, "urldefense": {"counts": {"unique": 5, "total": 6, "rewritten": 6}, "version": {"engine": "15"}}}, "durationSecs": 0.581787, "routes": ["default_inbound"], "isMsgReinjected": false, "disposition": "continue", "msgSizeBytes": 28953, "isMsgEncrypted": false, "routeDirection": "inbound", "actions": [{"action": "continue", "rule": "pass", "isFinal": true, "module": "pdr"}, {"action": "set-header", "rule": "EXT_add_tag", "module": "access"}, {"action": "continue", "rule": "EXT_add_tag", "module": "access"}, {"action": "add-header", "rule": "pass", "module": "spf"}, {"action": "continue", "rule": "pass", "module": "spf"}, {"action": "add-header", "rule": "clean", "module": "av"}, {"action": "continue", "rule": "clean", "module": "av"}, {"action": "continue", "rule": "pass", "module": "dmarc"}, {"action": "add-header", "rule": "inbound_notspam", "module": "spam"}], "startTime": "2019-05-07T12:48:05.173614-0600"}}&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:26:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/440486#M142499</guid>
      <dc:creator>swaguzari</dc:creator>
      <dc:date>2020-09-30T00:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Co-relation Search between two data sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/440487#M142500</link>
      <description>&lt;P&gt;ok, thanks for the sample data. I've updated the above search accordingly to cater for GUID case. Just used a &lt;CODE&gt;rename&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Please upvote/accept if it helped you&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 18:44:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/440487#M142500</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2019-05-08T18:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Co-relation Search between two data sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/440488#M142501</link>
      <description>&lt;P&gt;Done, thanks a ton!!! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 18:46:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/440488#M142501</guid>
      <dc:creator>swaguzari</dc:creator>
      <dc:date>2019-05-08T18:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Co-relation Search between two data sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/508166#M142502</link>
      <description>&lt;P&gt;Koshyk's response should function and will provide more context, but you're not using the data from both searches,&amp;nbsp; you'd likely see improved performance using a sub-search. This probably doesn't matter unless you have a significant volume of events being evaluated. Search below is untested.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=mail sourcetype=ppsmessagelog [index=mail sourcetype=proofpointtapsiem final_action=continue | stats values(GUID) as guid]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 18:52:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Co-relation-Search-between-two-data-sources/m-p/508166#M142502</guid>
      <dc:creator>tdwanders</dc:creator>
      <dc:date>2020-07-08T18:52:34Z</dc:date>
    </item>
  </channel>
</rss>

