For back ground please check the accepted answer for :
Best way to check email logs for recipients that are on a list
Scenario:
Searching for emails with a specific subject.
Need to know if any recipients are on a watch_list.csv (this has been accomplished by the following from somesoni2)
.... | lookup watch_list.csv emailaddress as recp OUTPUT flag | eval on_list=if(flag=1,"yes","no") | fields - flag ....
However, now I need the yes and the emailaddress that match the emailaddress on the watch_list.csv
Please provide an example.
Thank you
Just change your lookup command like this
..... | lookup watch_list.csv emailaddress as recp OUTPUT flag emailaddress | eval on_list=if(flag=1,"yes","no") | fields - flag
Just change your lookup command like this
..... | lookup watch_list.csv emailaddress as recp OUTPUT flag emailaddress | eval on_list=if(flag=1,"yes","no") | fields - flag
I knew you would come thru!!!! Thanks for all the help, I was adding emailaddress after the pipe... d'oh
Thanks again
um, is there a way to arrange the columns so that on_list column comes before emailaddress?
Are the email addresses stored in different field names? If so, try appending this to the end of your search
.. | where on_list="yes" AND email1=email2
Thank you, however Somesoni2's answer actually works better for me.
in other words, I want to add the emailaddress to the yes output....
eval on_list=if(flag=1, "Yes" --and the matching emailaddress
Thank you