Splunk Search

Phishing emails

of
New Member

Hi,

I want to create a search query that looks for users who have received phishing emails, clicked the link, or downloaded a file from the email.

Thanks

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What events do you have in Splunk to work with?

0 Karma

of
New Member

Hi,

Thanks for your reply. We have a WAF and firewall and ingest their logs in Splunk.

Regards,

 

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

WAF and firewall are typically _not_ solutions associated with email traffic or user's web-related behaviour so you might want to reconsider your sources list.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

OK so what do those events look like? What data do they contain? Please share some anonymised examples.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...