Splunk Search

How to query alerts by a specific personal domains?

brc55
Explorer

Hello,

I'm trying to put a query together to monitor/view emails being sent externally to a personal domain. 

i.e. johnsmith@corporation.com  to john@smith.com  or johnsmith@personalbusiness.com 

I'm not looking for external personal email addresses like johnsmith@gmail  or hotmail.com, etc. Specifically domains that have some correlation to the users name that appear to be a personal domain. 

index=***this is a corp. email index*** (from_domain="corp.com" AND rcpt_domain="??????")

Any help is appreciated! Thanks!

Labels (2)
Tags (3)
0 Karma

putnamblake
Path Finder

If the values you provided are fields or sources in your Splunk instance, and data for all outbound email domains is rolling into "rcpt_domain" why not exclude the known personal email domains you mentioned.

 

EX: index=Your_email_index from_domain=corp.com rcpt_domain NOT ("*gmail.com" OR "*hotmail.com" OR "*yahoo.com" OR "*aol.com") AND rcpt_domain=*

| rename from_domain as "Received From" , rcpt_domain as "Sent To Personal Domain"
|stats count by "Received From","Sent To Personal Domain"

 

0 Karma

brc55
Explorer

Thanks @putnamblake but unfortunately, that's not working. I think there may need to be some regex involved to help identify/match the from (corporate) email addresses to the personal domains.

0 Karma

putnamblake
Path Finder

Can you post a sample of the logs please?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...