Splunk Search

How to find the total number of users that receive a certain email?

Lye
Path Finder

Hello,

Please I need assistance. More than 300 people received a certain email. Some are still with the company while some are not. I need a query that can help me find the total number of people that are still with the company that receive this email. Please. 

Thank you

Labels (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

I understand that this could be a sensitive subject.  But you still need to share insight about the data available in Splunk that you think will help you make that determination.  To start,

  1. What is the data field that determines which user is with the company?
  2. What is the data field that determines which user has received said E-mail?
  3. Do the data field that determine the user who is with the company and the field that determines who received said E-mail in the same event?  In the same source?  In the same eventtype? etc.
  4. If the two types of data are in different events, is the data field that uniquely identifies a user the same in both types of events?
0 Karma

Lye
Path Finder

Thank you for your response. My superior took over the task

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...