Hi have a results from my mail index
say log look like below
sender=abc recipient=xyz@sample.com,ghi@nonsample.com country=abc
sender=def recipient=team@nonsample.com country=xyz
sender=gfh recipient=tip@nonsample.com country=efg
sender=abc recipient=none@sample.com,sample@nonsample.com country=pqr
I want to shows in a table only the non comma separated recipients only (as highlighted in bold where there are no multiple recipients)
can some one help me on this
Thanks all,
above didnt work..
however I tried
| eval recipient=split(recipient,","), rec_count=mvcount(rcpt)
| where rec_count=1
|table ...
and got the result
Hi @akshayinnamuri,
You can simply filter them by using below;
| search NOT sender=*,*
I think @scelikok meant
| search NOT recipient=*,*
Yes @ITWhisperer , thank you for correction