Splunk Search

How to find the total number of users that receive a certain email?

Lye
Path Finder

Hello,

Please I need assistance. More than 300 people received a certain email. Some are still with the company while some are not. I need a query that can help me find the total number of people that are still with the company that receive this email. Please. 

Thank you

Labels (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

I understand that this could be a sensitive subject.  But you still need to share insight about the data available in Splunk that you think will help you make that determination.  To start,

  1. What is the data field that determines which user is with the company?
  2. What is the data field that determines which user has received said E-mail?
  3. Do the data field that determine the user who is with the company and the field that determines who received said E-mail in the same event?  In the same source?  In the same eventtype? etc.
  4. If the two types of data are in different events, is the data field that uniquely identifies a user the same in both types of events?
0 Karma

Lye
Path Finder

Thank you for your response. My superior took over the task

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...