Each event found in my search, is always similar to the example below, but with a different email address found within the square brackets [email@myemaildomain].
<EMAIL><![CDATA[email@myemaildomain]]></EMAIL>
<BODY_TYPE>HTML</BODY_TYPE>
<PERSONALIZATION>
I am trying to understand and find a way to extract just the email address from the many events. My goal is to create an hourly alert and have it email me a text file with just those email addresses. The email alert I can do, but I am struggling to get the filtering of just the email address in the event.
Try the following:
| your search here
| spath input=yourinputfield
| table EMAIL
For example:
| stats count
| eval event = "<EMAIL><![CDATA[email@myemaildomain]]></EMAIL>
<BODY_TYPE>HTML</BODY_TYPE>
<PERSONALIZATION>"
| spath input=event
| table EMAIL
Output:
EMAIL
email@myemaildomain