Splunk Enterprise Security

input lookup file to search email traffic

hbfblueteam
New Member

Hi,

I am new to Splunk.

I have an input lookup file with some high risk internal email addresses in it . I want to build an alert which will trigger every time one of these addresses receives an external email with specific words in the subject line.

Index: mail
Lookup name: email_addresses.csv
Default Field for email address: recipient
Words in subject to look for: Payment, Account, Invoice

Any assistance would be much appreciated

Cheers,

0 Karma
1 Solution

starcher
Influencer

Build your base search for the index and sourcetype.
Make a wildcard lookup for the subject line.
Use a pattern like this

 index=mail sourcetype=PUTVALUEHERE | lookup emailaddresslookup receipt OUTPUT receipt as isFound | where isnotnull(isFound) | lookup emailsubjects subject OUTPUT subject as isFound | where isnotnull(isFound)

View solution in original post

0 Karma

starcher
Influencer

Build your base search for the index and sourcetype.
Make a wildcard lookup for the subject line.
Use a pattern like this

 index=mail sourcetype=PUTVALUEHERE | lookup emailaddresslookup receipt OUTPUT receipt as isFound | where isnotnull(isFound) | lookup emailsubjects subject OUTPUT subject as isFound | where isnotnull(isFound)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...