Splunk Search

How to find count of recipients by action where how many users received the email vs not for every event?

Woodpecker
Path Finder

Hi,

I have a search as below. I want to find count of recipients by action where how many users received the email vs not for every event

 

index=a sourcetype="a" 
| bucket span=4h _time
| stats values(action) as email_action,values(Sender) as Sender,dc(sender_email) as Sender_email_count,values(subject) as subject,dc(URL) as url_count, values(URL) as urls,values(filename) as files,values(recipients_list) as recipients_list by sender_name,_time 
| search (subject="*RE:*")

 

 Any help would be appreciated.. thank you!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats dc(sender_email) as Sender_email_count by action

Is this what you are after?

If not, please provide some anonymised sample events and some expected output to clarify your requirement

0 Karma
Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...