Splunk Search

How to display user list with number of attachment emails daily?

New Member

Hello All,

I have email exchange transactional data with below fields. Looking some data with span of 1day. Like how many emails sent by users having attachment vs no attachment. 

message_id, email_id, attachment_count, recipient_name

abc, nameA, 0, xyz


Expected result is :
date(like dd/mm/yy), email_ID,  HasAttachmnetcount, NoAttachmnet count. 

1/1/2022,nameA, 4, 3

I am able to write chart (over email_id by isattachmnet) and get data for the selected duration, but unable to list data splited day wise. 

Labels (2)
0 Karma

Esteemed Legend

Hi @Snehraj,

please try something like this:

| bin span=1d _time
| stats 
   count(eval(attachment_count=0)) AS NoAttachmnet
   count(eval(attachment_count>0)) AS HasAttachmnetcount
   BY _time email_id
| eval date=strftime(_time,"%d/%m/%Y")
| table date email_id HasAttachmnetcount NoAttachmnet



0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...