Splunk Enterprise Security

Subsearch results not matching special characters

SplunkNewbie18
New Member

Hi,

I'm trying to match email events which may consists of alphabets, numbers and special characters and do a count of the sender. However, those subjects with special characters (i.e. @, ", :, ]) is not picked up although its matching the subsearch condition. Anyone has any idea how to go about matching all character instances? Thanks!

index="A" sourcetype="A1" 
| search 
    [| search index="A" sourcetype="A1" subjects="[xxx]*" 
    | rex field=subjects "((?:\[.*\]\s+)(?<NewEmailSubject>(?:.*)))" 
    | eval subjects=NewEmailSubject
    | eval recipient=sender 
    | table subjects, recipient] 
  | stats values(subject) as subjects count by sender    
  | table sender, subjects, count
0 Karma

darrenfuller
Contributor

can you give a sample or two of data that is failing?

0 Karma

SplunkNewbie18
New Member

Oh sure! Some subjects sample:
1. Email Received @hotmail
2. [Hi!] FYA: 'Free' Ticket

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...