<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query for sender, recipient(s) and sender's IP in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711305#M240139</link>
    <description>&lt;P&gt;There is a Proofpoint add-on and we have it installed, but we need kind of bulk processing capabilities. For example, list all messages from a given sender, IP etc.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2025 19:18:02 GMT</pubDate>
    <dc:creator>SplunkUser001</dc:creator>
    <dc:date>2025-02-11T19:18:02Z</dc:date>
    <item>
      <title>Query for sender, recipient(s) and sender's IP</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711299#M240136</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Below is a sample for a single message from Proofpoint log. It looks simple, but I am struggling to write a query to pull sender (env_from value), recipient(s) (env_rcpt values) and IP address. As far as I understand X and S have the same values for given single message in the logs and will change from message to message. Any help will be greatly appreciated.&lt;/P&gt;&lt;P&gt;Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.436109+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mail cmd=env_from value=sender@company.com size= smtputf8= qid=44pnhtdtkf-1 tls= routes= notroutes=tls_fallback host=host123.company.com ip=10.10.10.10&lt;BR /&gt;Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.438453+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mail cmd=env_rcpt r=1 value=recipient.two@DifferentCompany.net orcpt=recipient.two@DifferentCompany.NET verified= routes= notroutes=RightFax,default_inbound,journal&lt;BR /&gt;Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.440714+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mail cmd=env_rcpt r=2 value=recipient.one@company.com orcpt=recipient.one@company.com verified= routes=default_inbound notroutes=RightFax,journal&lt;BR /&gt;Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.446326+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=data from=sender@company.com suborg=&lt;BR /&gt;Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.446383+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=data rcpt=recipient.two@DifferentCompany.net suborg=&lt;BR /&gt;Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.446405+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=data rcpt=recipient.one@company.com suborg=&lt;BR /&gt;Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.446639+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=data rcpt_routes= rcpt_notroutes=RightFax,journal data_routes= data_notroutes=&lt;BR /&gt;Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.450566+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=headers hfrom=sender@company.com routes= notroutes=&lt;BR /&gt;Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.455141+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mimelint cmd=getlint lint=&lt;BR /&gt;Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.455182+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mimelint cmd=getlint mime=1 score=0 threshold=100 duration=0.000&lt;BR /&gt;Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.455201+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mimelint cmd=getlint warn=0&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 18:08:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711299#M240136</guid>
      <dc:creator>SplunkUser001</dc:creator>
      <dc:date>2025-02-11T18:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: Query for sender, recipient(s) and sender's IP</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711301#M240137</link>
      <description>&lt;LI-CODE lang="markup"&gt;Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.436109+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mail cmd=env_from value=sender@company.com size= smtputf8= qid=44pnhtdtkf-1 tls= routes= notroutes=tls_fallback host=host123.company.com ip=10.10.10.10
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.438453+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mail cmd=env_rcpt r=1 value=recipient.two@DifferentCompany.net orcpt=recipient.two@DifferentCompany.NET verified= routes= notroutes=RightFax,default_inbound,journal
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.440714+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mail cmd=env_rcpt r=2 value=recipient.one@company.com orcpt=recipient.one@company.com verified= routes=default_inbound notroutes=RightFax,journal
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.446326+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=data from=sender@company.com suborg=
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.446383+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=data rcpt=recipient.two@DifferentCompany.net suborg=
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.446405+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=data rcpt=recipient.one@company.com suborg=
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.446639+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=data rcpt_routes= rcpt_notroutes=RightFax,journal data_routes= data_notroutes=
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.450566+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=headers hfrom=sender@company.com routes= notroutes=
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.455141+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mimelint cmd=getlint lint=
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.455182+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mimelint cmd=getlint mime=1 score=0 threshold=100 duration=0.000
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.455201+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mimelint cmd=getlint warn=0&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 11 Feb 2025 18:10:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711301#M240137</guid>
      <dc:creator>SplunkUser001</dc:creator>
      <dc:date>2025-02-11T18:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: Query for sender, recipient(s) and sender's IP</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711303#M240138</link>
      <description>&lt;P&gt;Have you checked &lt;A href="https://apps.splunk.com" target="_self"&gt;splunkbase&lt;/A&gt; for an add-on for the product you are using?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 18:15:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711303#M240138</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-02-11T18:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Query for sender, recipient(s) and sender's IP</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711305#M240139</link>
      <description>&lt;P&gt;There is a Proofpoint add-on and we have it installed, but we need kind of bulk processing capabilities. For example, list all messages from a given sender, IP etc.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 19:18:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711305#M240139</guid>
      <dc:creator>SplunkUser001</dc:creator>
      <dc:date>2025-02-11T19:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Query for sender, recipient(s) and sender's IP</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711325#M240147</link>
      <description>&lt;P&gt;You need to be more specific about your requirements. &amp;nbsp;Based on the sample you provided, what is the input and expected output of a query for sender? &amp;nbsp;What is the input and expected output of a query for recipients? &amp;nbsp;Are you combining given values of sender, recipients, sender's IP address in one query and expect some specific output? &amp;nbsp;Or are you expecting to give an input of a sender (email), and find out all recipients the sender has sent and the IP addresses this sender has used? &amp;nbsp;How does "&lt;SPAN&gt;X and S have the same values for given single message in the logs and will change from message to message" affect the outcome? &amp;nbsp;Is this information even relevant to your quest? (It didn't help that your sample data contains one X value and one S value.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;There are a million different ways to interpret "&lt;SPAN&gt;query to pull sender (env_from value), recipient(s) (env_rcpt values) and IP address;" this, combined with dozens of ways to implement each interpretation, it is impossible for volunteers to help you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you mean to say that a unique X, S combination marks one unique E-mail transaction, and you want to base your search on X and S values, all you need is from, ip, and rcpt. &amp;nbsp;Something like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats values(from) as sender values(ip) as ip values(rcpt) as recipients by s x&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your sample data should give&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;s&lt;/TD&gt;&lt;TD&gt;x&lt;/TD&gt;&lt;TD&gt;sender&lt;/TD&gt;&lt;TD&gt;ip&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;recipients&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;44pnhtdtkf&lt;/TD&gt;&lt;TD&gt;44pnhtdtkf-1&lt;/TD&gt;&lt;TD&gt;sender@company.com&lt;/TD&gt;&lt;TD&gt;10.10.10.10&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;recipient.one@company.com&lt;/DIV&gt;&lt;DIV class=""&gt;recipient.two@DifferentCompany.net&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Is this what you are looking for?&lt;/P&gt;&lt;P&gt;Here is an emulation of your sample. &amp;nbsp;Play with it and compare with real data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval data = split("Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.436109+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mail cmd=env_from value=sender@company.com size= smtputf8= qid=44pnhtdtkf-1 tls= routes= notroutes=tls_fallback host=host123.company.com ip=10.10.10.10
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.438453+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mail cmd=env_rcpt r=1 value=recipient.two@DifferentCompany.net orcpt=recipient.two@DifferentCompany.NET verified= routes= notroutes=RightFax,default_inbound,journal
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.440714+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mail cmd=env_rcpt r=2 value=recipient.one@company.com orcpt=recipient.one@company.com verified= routes=default_inbound notroutes=RightFax,journal
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.446326+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=data from=sender@company.com suborg=
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.446383+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=data rcpt=recipient.two@DifferentCompany.net suborg=
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.446405+00:00 host filter_instance1[1394]: rprt s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=data rcpt=recipient.one@company.com suborg=
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.446639+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=data rcpt_routes= rcpt_notroutes=RightFax,journal data_routes= data_notroutes=
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.450566+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=session cmd=headers hfrom=sender@company.com routes= notroutes=
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.455141+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mimelint cmd=getlint lint=
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.455182+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mimelint cmd=getlint mime=1 score=0 threshold=100 duration=0.000
Feb 11 10:04:12 host.company.com 2025-02-11T15:04:12.455201+00:00 host filter_instance1[1394]: info s=44pnhtdtkf m=1 x=44pnhtdtkf-1 mod=mimelint cmd=getlint warn=0", "
")
| mvexpand data
| rename data as _raw
| extract
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 05:02:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711325#M240147</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2025-02-12T05:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Query for sender, recipient(s) and sender's IP</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711341#M240148</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273359"&gt;@SplunkUser001&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;where did you installed the add-on?&lt;/P&gt;&lt;P&gt;it must be installed in the Forwarder and on the Search Head.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 07:23:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Query-for-sender-recipient-s-and-sender-s-IP/m-p/711341#M240148</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-02-12T07:23:18Z</dc:date>
    </item>
  </channel>
</rss>

