Splunk Search

How to find the total number of users that receive a certain email?

Lye
Path Finder

Hello,

Please I need assistance. More than 300 people received a certain email. Some are still with the company while some are not. I need a query that can help me find the total number of people that are still with the company that receive this email. Please. 

Thank you

Labels (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

I understand that this could be a sensitive subject.  But you still need to share insight about the data available in Splunk that you think will help you make that determination.  To start,

  1. What is the data field that determines which user is with the company?
  2. What is the data field that determines which user has received said E-mail?
  3. Do the data field that determine the user who is with the company and the field that determines who received said E-mail in the same event?  In the same source?  In the same eventtype? etc.
  4. If the two types of data are in different events, is the data field that uniquely identifies a user the same in both types of events?
0 Karma

Lye
Path Finder

Thank you for your response. My superior took over the task

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...