Splunk Enterprise Security

input lookup file to search email traffic

hbfblueteam
New Member

Hi,

I am new to Splunk.

I have an input lookup file with some high risk internal email addresses in it . I want to build an alert which will trigger every time one of these addresses receives an external email with specific words in the subject line.

Index: mail
Lookup name: email_addresses.csv
Default Field for email address: recipient
Words in subject to look for: Payment, Account, Invoice

Any assistance would be much appreciated

Cheers,

0 Karma
1 Solution

starcher
Influencer

Build your base search for the index and sourcetype.
Make a wildcard lookup for the subject line.
Use a pattern like this

 index=mail sourcetype=PUTVALUEHERE | lookup emailaddresslookup receipt OUTPUT receipt as isFound | where isnotnull(isFound) | lookup emailsubjects subject OUTPUT subject as isFound | where isnotnull(isFound)

View solution in original post

0 Karma

starcher
Influencer

Build your base search for the index and sourcetype.
Make a wildcard lookup for the subject line.
Use a pattern like this

 index=mail sourcetype=PUTVALUEHERE | lookup emailaddresslookup receipt OUTPUT receipt as isFound | where isnotnull(isFound) | lookup emailsubjects subject OUTPUT subject as isFound | where isnotnull(isFound)
0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...