Splunk Search

How to find the total number of users that receive a certain email?

Lye
Path Finder

Hello,

Please I need assistance. More than 300 people received a certain email. Some are still with the company while some are not. I need a query that can help me find the total number of people that are still with the company that receive this email. Please. 

Thank you

Labels (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

I understand that this could be a sensitive subject.  But you still need to share insight about the data available in Splunk that you think will help you make that determination.  To start,

  1. What is the data field that determines which user is with the company?
  2. What is the data field that determines which user has received said E-mail?
  3. Do the data field that determine the user who is with the company and the field that determines who received said E-mail in the same event?  In the same source?  In the same eventtype? etc.
  4. If the two types of data are in different events, is the data field that uniquely identifies a user the same in both types of events?
0 Karma

Lye
Path Finder

Thank you for your response. My superior took over the task

0 Karma
Get Updates on the Splunk Community!

Splunk is Nurturing Tomorrow’s Cybersecurity Leaders Today

Meet Carol Wright. She leads the Splunk Academic Alliance program at Splunk. The Splunk Academic Alliance ...

Part 2: A Guide to Maximizing Splunk IT Service Intelligence

Welcome to the second segment of our guide. In Part 1, we covered the essentials of getting started with ITSI ...

Part 1: A Guide to Maximizing Splunk IT Service Intelligence

As modern IT environments continue to grow in complexity and speed, the ability to efficiently manage and ...