I want to exlude specific domains from both sender and receipient.
for example I have abc.com domain and have one lookup file with legitiamate domain names.
Now I want to see a emails which is not include either as sender or receipient in that lookup file.
OR in simple words how can I compare lookup values againt two fields(sender and receipient)
Hi @rashid47010
Try this
| makeresults
| eval sender="test@test.com"
| eval receiver="test1@test.com"
| rex field=sender "@(?P<senderdomain>.*)"
| lookup domainlookup domain as senderdomain OUTPUT domain as senderflag
| rex field=receiver "@(?P<receiverdomain>.*)"
| lookup domainlookup domain as receiverdomain OUTPUT domain as receiverflag
| where isnull(senderflag) AND isnull(receiverflag)
lookup: domainlookup
domain
abc.com
test.com
@rashid47010, have you tried?
Its solved?