So we did manage to get this working with help from the guy who built the addon. I'll give you an example of a Splunk query that helped me index="example" #This is our authentication index
| table username
| eval username_email=if(match(username,"[A-Z0-9._%+-]+@[A-Z0-9.-]+\.[A-Z]{2,}"),username,null())
| where isnotnull (username_email)
| table username_email
| emailvalidation field="username_email"
... View more