Hi there, I have a csv lookup file consisting of sender email addresses. I'd like to search the splunk logs for all the entries with these SenderAddresses over the last 90 days to determine what FromIP they have. What search syntax do I use? file has been uploaded to Splunk and is called AllSenders.csv. it has heading email, flag...all the flag are set to 1 since I want to search them all. In general, to search the logs for email i use: index=app_messagetrace sourcetype=ms:o365:reporting:messagetrace Thanks in advance....let me know what other info you need to help 🙂
... View more