Splunk Enterprise Security

input lookup file to search email traffic

hbfblueteam
New Member

Hi,

I am new to Splunk.

I have an input lookup file with some high risk internal email addresses in it . I want to build an alert which will trigger every time one of these addresses receives an external email with specific words in the subject line.

Index: mail
Lookup name: email_addresses.csv
Default Field for email address: recipient
Words in subject to look for: Payment, Account, Invoice

Any assistance would be much appreciated

Cheers,

0 Karma
1 Solution

starcher
Influencer

Build your base search for the index and sourcetype.
Make a wildcard lookup for the subject line.
Use a pattern like this

 index=mail sourcetype=PUTVALUEHERE | lookup emailaddresslookup receipt OUTPUT receipt as isFound | where isnotnull(isFound) | lookup emailsubjects subject OUTPUT subject as isFound | where isnotnull(isFound)

View solution in original post

0 Karma

starcher
Influencer

Build your base search for the index and sourcetype.
Make a wildcard lookup for the subject line.
Use a pattern like this

 index=mail sourcetype=PUTVALUEHERE | lookup emailaddresslookup receipt OUTPUT receipt as isFound | where isnotnull(isFound) | lookup emailsubjects subject OUTPUT subject as isFound | where isnotnull(isFound)
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...