Splunk Search

Multiple email domains..

Brian_Osburn
Builder

I've upgraded from Version 1.01 to 1.1 today, and I'm having some issues around users with multiple email addresses.

For example, some parts of our company are using first.last@companyname1.com, while some of us are using firstinitallastname@companyname2.com.

Is there anyway to account for this in the application?

In addition, under client behavior - mailbox store overview, alot of the usernames are listed as @UNKNOWN..

Any help around this?

0 Karma
1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

You need to edit the domain_aliases.csv and active_directory.csv to account for the variance in the information. This is documented on http://docs.splunk.com

View solution in original post

ahall_splunk
Splunk Employee
Splunk Employee

You need to edit the domain_aliases.csv and active_directory.csv to account for the variance in the information. This is documented on http://docs.splunk.com

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...