Splunk Search

Ironport: How to get all 'from' emails for specific user

New Member

Hello, I am trying to run a search to get the "Email_From_Address" of a specific user within ironport.

Can someone please provide the search that would produce that result, please.

For example, I want to know all the from emails that came from user "Joe.Smith@deomain.com"

Any assistance in this regard will be really appreciated!

Thank you in advance for all your help.


0 Karma


What is the format of your ironport log events? Can you share a sanitized version of a few events?

0 Karma


@cosmo360 can you share your logs please. Id the email_from_address parsed or you need to extract it?

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...