Splunk Search

How to find the total number of users that receive a certain email?

Lye
Path Finder

Hello,

Please I need assistance. More than 300 people received a certain email. Some are still with the company while some are not. I need a query that can help me find the total number of people that are still with the company that receive this email. Please. 

Thank you

Labels (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

I understand that this could be a sensitive subject.  But you still need to share insight about the data available in Splunk that you think will help you make that determination.  To start,

  1. What is the data field that determines which user is with the company?
  2. What is the data field that determines which user has received said E-mail?
  3. Do the data field that determine the user who is with the company and the field that determines who received said E-mail in the same event?  In the same source?  In the same eventtype? etc.
  4. If the two types of data are in different events, is the data field that uniquely identifies a user the same in both types of events?
0 Karma

Lye
Path Finder

Thank you for your response. My superior took over the task

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...