Splunk Enterprise Security

How can we monitor if a user clicked on a phishing link or button in an email?

Sasquatchatmars
Communicator

Hi everybody,

We have a stream forwarder which sends every mail that enters in an index. It contains everything from the mail. I want to know if it is possible to see if the receiver of the mail opened the link that is in the mail or in the button?

Thank you,

Sasquatchatmars

 

0 Karma

lakshman239
Influencer

If you have web proxy logs, you can see the urls clicked by the user. You can then link the phishing url/user in proxy logs with the email events to understand how many users have clicked the malicious link

0 Karma

Sasquatchatmars
Communicator

Hi @lakshman239,

Thank you for your reply, can you tell me what the search would look like? 

Thank you,

Sasquatchatmars

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Apart from the emails, what other data do you have in splunk?

0 Karma

Sasquatchatmars
Communicator

Hi thanks for your reply,

I have the security logs of every domain controller. But if it needs other logs we can maybe put in a request to forward them. But in order to do that I need to know what exactly and then know how to search for it. 

Thank you,

Sasquatchatmars

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...