Splunk Search

How to show the recipient or To field from Ironport logs in a Splunk search?

rockyrc
New Member

I can only view the recipient or To in the email from the Event Actions --> Show Source page. I want to show it in the main search.

0 Karma

Jeremiah
Motivator

Are you searching by the subject? Since the ironport logs the recipient, sender, and subject in separate events, you have to search by message (MID) to see all of the fields. Do you have field extractions setup for the Ironport logs? Typically, what you would want to do is search for the subject in a subsearch, then pass a list of MIDs to the main search, so that you can see all of the events associated with that particular subject. This search should work, even if you aren't extracting the Ironport fields. You need to replace sourcetype=ironport with whatever search terms you use to find your ironport logs (maybe a different sourcetype, or index, etc), and replace the My Subject with the keywords from your subject in the subsearch.

sourcetype=ironport [search sourcetype=ironport My Subject | rex "MID\s(?<MID>\d+)" | dedup MID | fields MID | rename MID AS query | format] | rex "MID\s(?<MID>\d+)" | rex "Subject\s(?<subject>.*)" | rex "To:\s\<(?<recipient>[^\>]+)" | rex "From:\s\<(?<sender>[^\>]+)" | stats values(sender) AS Sender values(recipient) AS recipient values(subject) AS Subject by MID

If you search your Ironport data, and you do have fields extracted already (like subect, to, from, etc.). Then you can still use the above search. Just exclude the rex statements and substitute in your field names. If you don't have the fields extracted already, I recommend you look at deploying the add-on for ESA (Ironport) as it will include field extractions so you don't have to create them yourself.

https://splunkbase.splunk.com/app/1761/#/overview

0 Karma

rockyrc
New Member

I am searching for all emails within different timeframes not specific to any subject at the moment. I am not sure if they have field extractions setup for the ironport logs, I will have to check on this. I just need to perform a search if possible with the current setup, to show the: Sender, Recipient, Subject, Message..etc. Thanks for the help.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...