I want to extract the recipient and sender domains from e-mail addresses that appear in my logs. I can extract them from _raw:
EXTRACT-ToDomain = (?i)to=<[^@]*@(?<ToDomain>[^>]*)
EXTRACT-FromDomain = (?i)From=<[^@]*@(?<FromDomain>[^>]*)
or from existing fields:
EXTRACT-ToDomain = @(?P<ToDomain>[^>]*) in to
EXTRACT-FromDomain = @(?P<FromDomain>[^>]*) in From
Is one method more efficient than the other?
Strictly speaking the second option would be a bit more efficient, but in reality I highly doubt you would be able to notice any difference.
Strictly speaking the second option would be a bit more efficient, but in reality I highly doubt you would be able to notice any difference.