Splunk Search

How to find count of recipients by action where how many users received the email vs not for every event?

Woodpecker
Path Finder

Hi,

I have a search as below. I want to find count of recipients by action where how many users received the email vs not for every event

 

index=a sourcetype="a" 
| bucket span=4h _time
| stats values(action) as email_action,values(Sender) as Sender,dc(sender_email) as Sender_email_count,values(subject) as subject,dc(URL) as url_count, values(URL) as urls,values(filename) as files,values(recipients_list) as recipients_list by sender_name,_time 
| search (subject="*RE:*")

 

 Any help would be appreciated.. thank you!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats dc(sender_email) as Sender_email_count by action

Is this what you are after?

If not, please provide some anonymised sample events and some expected output to clarify your requirement

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...