Splunk Search

checking list of email domains appear in a field

ChrisCLewis
Communicator

I have a field (recipient) which contains all the recipients that an email was sent to. I also have a lookupcsv file with field (watch) which list of domain address to look for e.g. gmail.com

How can I check to see if a domain from the lookup csv appears anywhere within the recipient field - I need it as a filter so I can do work with the remainder of the records data

I have gotten closet using
|join recipient [|inputlookup check.csv |rename watch as recipient|fields recipient]

but it is not returning enough matches.

Many thanks for any pointers

Tags (1)
0 Karma
1 Solution

dkeck
Influencer

Hi,

if you have a lookup with a field watch and lets say the value of "yes" and "no", you can use the | lookup command

like this : | lookup check.csv recipient OUTPUT watch you could add | fields recipient watch (assuming the field with the domains within the check.csv is called recipient)

then you can search for the value yes within the field watch your search| lookup check.csv recipient OUTPUT watch | fields recipient watch | where watch="yes"

View solution in original post

0 Karma

dkeck
Influencer

please accept answer if it was helpful 🙂

0 Karma

tmuthuk
Path Finder

Hi

Can you try this ?

Extract Domain from the recipient field and join with the Check.csv . Try the below query

| rex field=Recipient "\@(?[^.]*)" | eval Found= "N" | table Recipient Domain | join Domain [ | inputlookup Check.csv | eval Found="Y" | table Domain Found]

0 Karma

dkeck
Influencer

Hi,

if you have a lookup with a field watch and lets say the value of "yes" and "no", you can use the | lookup command

like this : | lookup check.csv recipient OUTPUT watch you could add | fields recipient watch (assuming the field with the domains within the check.csv is called recipient)

then you can search for the value yes within the field watch your search| lookup check.csv recipient OUTPUT watch | fields recipient watch | where watch="yes"

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...