I cant figure this out. I cant get my query to check a lookup to verify if the identified recipient from the phish logs is in the useremail field.
Still struggling with splunk, thanks for the help.
Like this:
Your Search Here That Has recipient Field
| lookup YourLookupNameHere.csv username AS recipient OUTPUT username AS MATCHED
| where isnotnull(MATCHED)
Hi williamsmew, please check this splunk answer, maybe this can help you out with your issue
-> https://answers.splunk.com/answers/588630/understanding-the-lookup-command.html
Can you post a sample of your query please?
and a sample of your data