<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: extract subject from maillog in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87167#M22289</link>
    <description>&lt;P&gt;Hi Ayn, here is a sample of the logfile, I want to extract the subject:&lt;/P&gt;

&lt;P&gt;Mon Jul  2 10:20:38 2012 Info: Start MID 62771585 ICID 33896658&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 ICID 33896658 From: &amp;lt;*****&lt;STRONG&gt;&lt;EM&gt;&amp;gt;&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: Delivery start DCID 24405838 MID 62771584 to RID [0]&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 ICID 33896658 RID 0 To: &amp;lt;&lt;/EM&gt;&lt;/STRONG&gt;*&lt;STRONG&gt;&lt;EM&gt;&amp;gt;&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 Message-ID '&lt;A href="mailto:2B2E0EB229A8F44AB8C55D5E296BCFC40C584F@SCOMP0934.wurnet.nl"&gt;2B2E0EB229A8F44AB8C55D5E296BCFC40C584F@SCOMP0934.wurnet.nl&lt;/A&gt;'&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 Subject 'FW: Postbus AgroFood vanaf vrijdag 17:00 VOL: opnieuw inzenden!!'&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 ready 19724 bytes from &amp;lt;&lt;/EM&gt;&lt;/STRONG&gt;****&amp;gt;&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 matched all recipients for per-recipient policy DEFAULT in the outbound table&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 interim AV verdict using Sophos CLEAN&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 antivirus negative &lt;/P&gt;</description>
    <pubDate>Mon, 02 Jul 2012 08:55:03 GMT</pubDate>
    <dc:creator>dictudatacom</dc:creator>
    <dc:date>2012-07-02T08:55:03Z</dc:date>
    <item>
      <title>extract subject from maillog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87164#M22286</link>
      <description>&lt;P&gt;Hi, I want to extract the 'subjects' from my SMTP maillog but the regex I have built doesn't seem to work. I have built the same type of regex to extract the FROM en TO fields and that works so I'm puzzled why it doesn't extract the subjects...&lt;/P&gt;

&lt;P&gt;Regex looks like this:&lt;/P&gt;

&lt;P&gt;(?i) subject &amp;lt;(?P&lt;ONDERWERP&gt;[^&amp;gt;]*)&lt;/ONDERWERP&gt;&lt;/P&gt;

&lt;P&gt;Can anyone help me out ? Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2012 09:47:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87164#M22286</guid>
      <dc:creator>dictudatacom</dc:creator>
      <dc:date>2012-06-29T09:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: extract subject from maillog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87165#M22287</link>
      <description>&lt;P&gt;Please include a log sample. Without it it's hard to build a regex that should match.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2012 11:30:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87165#M22287</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-06-29T11:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: extract subject from maillog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87166#M22288</link>
      <description>&lt;P&gt;have you tried using the "extract fields" dropdown from one of the events? &lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2012 13:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87166#M22288</guid>
      <dc:creator>jfraiberg</dc:creator>
      <dc:date>2012-06-29T13:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: extract subject from maillog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87167#M22289</link>
      <description>&lt;P&gt;Hi Ayn, here is a sample of the logfile, I want to extract the subject:&lt;/P&gt;

&lt;P&gt;Mon Jul  2 10:20:38 2012 Info: Start MID 62771585 ICID 33896658&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 ICID 33896658 From: &amp;lt;*****&lt;STRONG&gt;&lt;EM&gt;&amp;gt;&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: Delivery start DCID 24405838 MID 62771584 to RID [0]&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 ICID 33896658 RID 0 To: &amp;lt;&lt;/EM&gt;&lt;/STRONG&gt;*&lt;STRONG&gt;&lt;EM&gt;&amp;gt;&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 Message-ID '&lt;A href="mailto:2B2E0EB229A8F44AB8C55D5E296BCFC40C584F@SCOMP0934.wurnet.nl"&gt;2B2E0EB229A8F44AB8C55D5E296BCFC40C584F@SCOMP0934.wurnet.nl&lt;/A&gt;'&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 Subject 'FW: Postbus AgroFood vanaf vrijdag 17:00 VOL: opnieuw inzenden!!'&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 ready 19724 bytes from &amp;lt;&lt;/EM&gt;&lt;/STRONG&gt;****&amp;gt;&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 matched all recipients for per-recipient policy DEFAULT in the outbound table&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 interim AV verdict using Sophos CLEAN&lt;BR /&gt;
Mon Jul  2 10:20:38 2012 Info: MID 62771585 antivirus negative &lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2012 08:55:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87167#M22289</guid>
      <dc:creator>dictudatacom</dc:creator>
      <dc:date>2012-07-02T08:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: extract subject from maillog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87168#M22290</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Did you get an answer for this - trying to do this myself. My email subjects differ so I want to table them all &lt;/P&gt;

&lt;P&gt;How did you end up extracting the subject lines?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Sue&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2013 03:52:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87168#M22290</guid>
      <dc:creator>suepfarrell</dc:creator>
      <dc:date>2013-08-16T03:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: extract subject from maillog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87169#M22291</link>
      <description>&lt;P&gt;Your regex should looking something like this.&lt;/P&gt;

&lt;P&gt;Subject.'(?&lt;SUBJECT&gt;.*)'&lt;/SUBJECT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2013 05:04:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87169#M22291</guid>
      <dc:creator>jstockamp</dc:creator>
      <dc:date>2013-08-16T05:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: extract subject from maillog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87170#M22292</link>
      <description>&lt;P&gt;Thx jstockamp - that didn't quite work. I will give more detail in my own question I think. About to go set one up now.&lt;BR /&gt;
Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2013 05:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/extract-subject-from-maillog/m-p/87170#M22292</guid>
      <dc:creator>suepfarrell</dc:creator>
      <dc:date>2013-08-16T05:54:21Z</dc:date>
    </item>
  </channel>
</rss>

