Splunk Enterprise

dovecot Logs

siemsplunk
Explorer

Hello team,

Am working with dovecot logs-- it's a mail logs.

I managed to integrate it with Splunk through syslog.

it gives me the logs in this format (Attached screenshot)

Now, I want to create a new field to have value of to/receiver
From the screenshot the value of to/receiver is in lda(value)

NOTE: on the below screenshot I dont have to/receiver values i just have from/sender and subject

siemsplunk_0-1721797503738.png

 

Help me please !


0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

You can do inline extraction with rex, e.g.

| rex "lda\((?<to>[^\)]*)\)"

which will extract a new field called to from the portion between the brackets 

You can also set this up as a field extraction - see Fields->Field Extractions and create a new field extraction there using the regex above and then, if lda(xxx) exists in your data, you will get a field called to

 

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

You can do inline extraction with rex, e.g.

| rex "lda\((?<to>[^\)]*)\)"

which will extract a new field called to from the portion between the brackets 

You can also set this up as a field extraction - see Fields->Field Extractions and create a new field extraction there using the regex above and then, if lda(xxx) exists in your data, you will get a field called to

 

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...