is there any splunk query to search for send, recipient and subject in msexchange email logs? I know there is msexchange app but could it be done via simple query, regex? thanks for your help
You will want to group all your logs by "internal_message_id" or "MID" to do so, you can use the "transaction" command :
Index=email sourcetype=msexchange | transaction MID
As you'll see transaction is quiet slow, I'll recommand using a groupby instead, It should look something like this :
Index=email sourcetype=msexchange | stats values(recipient) AS recipient, values(sender) AS sender, values(subject) AS subject by MID
what's session field?
@to4kawa this is regarding sourcetype=MSExchange:2013:MessageTracking so basically using it to parse send receive and subject
@to4kawa thanks for your response I am looking for email sender, recipient and subject fields
what's the results of searching
sender@domain OR subject OR recipient@domain?