Reporting

Detecting spam

bryansocito
New Member

Hi All,

I'm creating a dashboard where it will show if 1 email is sent to multiple recipients (spam) - same sender, same subject, multiple recipients. So basically it's a threat detection via email. Is this possible?

alt text

Cheers,
Bryan

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Perhaps this will get you started.

<your search for email> | stats count(recipient) as recipients by Sender, Subject | where recipients > 3 | ...
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps this will get you started.

<your search for email> | stats count(recipient) as recipients by Sender, Subject | where recipients > 3 | ...
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...