Splunk Search

How to find count of recipients by action where how many users received the email vs not for every event?

Woodpecker
Path Finder

Hi,

I have a search as below. I want to find count of recipients by action where how many users received the email vs not for every event

 

index=a sourcetype="a" 
| bucket span=4h _time
| stats values(action) as email_action,values(Sender) as Sender,dc(sender_email) as Sender_email_count,values(subject) as subject,dc(URL) as url_count, values(URL) as urls,values(filename) as files,values(recipients_list) as recipients_list by sender_name,_time 
| search (subject="*RE:*")

 

 Any help would be appreciated.. thank you!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats dc(sender_email) as Sender_email_count by action

Is this what you are after?

If not, please provide some anonymised sample events and some expected output to clarify your requirement

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...