Getting Data In

Postfix_logs_format

abusayeed
New Member

I have sent a mail. And mail server gives me logs like these.

Feb 27 11:30:11 mail postfix/qmgr[8620]: 24C4C681F19: from=kalam@example.com, size=8814, nrcpt=1 (queue active)
Feb 27 11:30:11 mail postfix/amavis/smtp[50690]: 24C4C681F19: to=salam@example.com, relay=127.0.0.1[127.0.0.1]:10024, delay=2.1, delays=1.2/0.01/0/0.93, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as F3433681F7C)

I want to build a search based on the from address, but do stats on the status (separate counts for deffered, sent, reject etc.). Anyway I could make splunk realize these two events are related?

Tags (1)
0 Karma

p_gurav
Champion
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...