I used the query index="botsv2" Amber. I found a capture_hostname: matar
Which e-mail seems to be linked to "matar"?
And who sends the person attach to the "feed" email to?
This is from https://github.com/splunk/botsv2