Hi, I'm writing a splunk query to find emails with specific file types attached I have the regex working which pulls the files and also extracts the file extensions which I'll be using for data collection purposes later. I will then use this extracted file extension to search and return specific emails containing files with said extension (hope that makes sense) The problem is that when I use |where FileExtension=".doc" I get events returned where it contains a .doc file which is fine. But it also shows all the other files attached which I do not want. For example I want my output to be sender recipient file.doc But what I am getting is sender recipient file.doc file.a file.b file.c file.d Is there any way to do some kind of exclusive search that will ignore the extra data in the file field that are not .doc's as they are of no interest to me at the moment?
... View more