Splunk Search

Regex to extract email domain name

davidcraven02
Communicator

I have two regexes below which are pulling the domain name of the email sender (from). i.e linkedin.com, amazones.com.

However I cant create one regex to pull them both in one as they aren't always in the same format.

index=fortimail source=/var/log/messages/splunk/fortimail/*-fortimail.log 
| dedup   date, time, to, from, domain, subject
| rex field=from "(.*@.*\.(?<domainname>.*\..*)$)"
| rex field=from ".*@(?<domainname2>.*\..*)$" 
| table date, time, to, from, domainname, domainname2, subject, message_length

alt text

Tags (2)
0 Karma
1 Solution

BearMormont
Path Finder

This should work with any domain (not just .com):

rex field=from ".*?(?<domainname>[\w]+\.[\w]+)$"

Edit:
Example - https://regex101.com/r/1uTWmD/1/

View solution in original post

tiagofbmm
Influencer

Try this generic example

| makeresults 
| eval to="tiago@lalala.domain1.com" 
| append [ | makeresults 
| eval to="tiago@domain2.com" ]
| append [ | makeresults | eval to="firstname.surname@test.co.uk" ]
| rex field=to "@(.*\.)*(?<Domain>.*\..*)"

The test.co.uk is an outlier to this rule? Did you want domain to be test.co.uk? Then you have the same exact format but you want two different behaviours?

Regex doesn't work like that

0 Karma

BearMormont
Path Finder

This should work with any domain (not just .com):

rex field=from ".*?(?<domainname>[\w]+\.[\w]+)$"

Edit:
Example - https://regex101.com/r/1uTWmD/1/

davidcraven02
Communicator

It doesn't work with this example: firstname.surname@test.co.uk

Any thoughts?

0 Karma

elliotproebstel
Champion

This is a generically difficult problem. Differentiating domains from subdomains requires a priori knowledge of all top level domains (TLDs), because a domain is really just something.valid-tld, where something is composed of letters, numbers, and hyphens (if the hyphens are surrounded on both sides by letters, numbers, or other hypens; hyphens may not be the first or last character in a domain name).

To that end, you could build something yourself that does this, but you'd be reinventing the wheel. You might want to check out this blog post on UT_parsing, which describes a few Splunk add-ons/apps that you could leverage in your work.

davidcraven02
Communicator

Thank you! Yes i thought I was maybe over complicating it.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...