Reporting

Cisco email security(ironport)

rashid47010
Communicator

splunk is not showing the cisco email security event as one event. each log line is showing as one individual event

0 Karma

rashid47010
Communicator

somehow I manage to arrange the event under one event occurrence. below is the query.

index=cisco_es | rex "MID\s(?\d+)" | rex "DCID\s(?\d+)" | rex "ICID\s(?\d+)" | transaction MID_New DCID_New ICID_New maxevents=30 endswith="Message done" | search MID_New="xxxxx"

0 Karma

rashid47010
Communicator

now I want to enhance the search. I want to list all the attachment and either the email get delivered or not.

Please help me to conclude this.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...