All Apps and Add-ons

Extracting results to a csv file

New Member



I was wondering if I could do two things. I am new to splunk so please have mercy on me. I am looking for a query that will search inside a mailbox and look for a certain subject. Once it find that subject I would like to extract the recipients to a csv file for the last 40 days. Is this possible?


Labels (1)
0 Karma


If your mailboxes are indexed in Splunk then Splunk can search them.  Splunk cannot reach out to your email provider to search your mail.

With your email indexed, Splunk can search for the specified subject and extract the recipients (if in the index).  The final results of the search can be saved to a CSV file by using the outputcsv command.  See

If this reply helps you, an upvote would be appreciated.
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!