Splunk Search

Extract domain part of list of emails addresses.

dhabbal
Explorer

Hi,

My results are a bunch of email address, I want to display them in table grouped by their domains.

What's the best way to achieve this?

Thanks!

Tags (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi dhabbal,
if your emails are in a field called "email", you could run a search like this:

index=my_index
| rex field=email "\@(?<domain>[^ ]*)"
| stats dc(email) AS num_email BY domain

in this way you have the count of different emails in your logs.

If in addition you want also the name of your emails, you could run:

index=my_index
| rex field=email "\@(?<domain>[^ ]*)"
| stats values(email) AS email dc(email) AS num_email BY domain

If at least, you want the number of emails ordered by domain, you could run:

index=my_index
| stats count BY email
| rex field=email "\@(?<domain>[^ ]*)"
| sort domain
| table domain email count

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi dhabbal,
if your emails are in a field called "email", you could run a search like this:

index=my_index
| rex field=email "\@(?<domain>[^ ]*)"
| stats dc(email) AS num_email BY domain

in this way you have the count of different emails in your logs.

If in addition you want also the name of your emails, you could run:

index=my_index
| rex field=email "\@(?<domain>[^ ]*)"
| stats values(email) AS email dc(email) AS num_email BY domain

If at least, you want the number of emails ordered by domain, you could run:

index=my_index
| stats count BY email
| rex field=email "\@(?<domain>[^ ]*)"
| sort domain
| table domain email count

Bye.
Giuseppe

0 Karma

dineshraj9
Builder

Can you post a sample event?

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...