Splunk Search

Searching msexchange logs

New Member

is there any splunk query to search for send, recipient and subject in msexchange email logs? I know there is msexchange app but could it be done via simple query, regex? thanks for your help

0 Karma

Communicator

You will want to group all your logs by "internalmessageid" or "MID" to do so, you can use the "transaction" command :

 Index=email sourcetype=msexchange | transaction MID 

As you'll see transaction is quiet slow, I'll recommand using a groupby instead, It should look something like this :

Index=email sourcetype=msexchange  | stats values(recipient) AS recipient, values(sender) AS sender, values(subject) AS subject by MID

3no

0 Karma

Ultra Champion

what's session field?

0 Karma

New Member

@to4kawa this is regarding sourcetype=MSExchange:2013:MessageTracking so basically using it to parse send receive and subject

0 Karma

Ultra Champion
0 Karma

New Member

@to4kawa thanks for your response I am looking for email sender, recipient and subject fields

0 Karma

Ultra Champion

what's the results of searching sender@domain OR subject OR recipient@domain?

0 Karma