Splunk Enterprise

How to compare two approximately similar email addresses ?

galsegal
Explorer

Hello All,

I'm trying to create a query for finding if a sender email address is similar to recipient address.

for example -

in this case below I need to return TRUE-

sender:

john.smith@example.com

recipient:

johnsmith@gmail.com (or even recipient like-  johns@gmail.com)

Is there a way to utilize spunk ES to search such approximate string comparison?

 

Thanks!!

Labels (2)
0 Karma

galsegal
Explorer

Guess this is out of scope? 😕

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.