Splunk Search

How to show the recipient or To field from Ironport logs in a Splunk search?

rockyrc
New Member

I can only view the recipient or To in the email from the Event Actions --> Show Source page. I want to show it in the main search.

0 Karma

Jeremiah
Motivator

Are you searching by the subject? Since the ironport logs the recipient, sender, and subject in separate events, you have to search by message (MID) to see all of the fields. Do you have field extractions setup for the Ironport logs? Typically, what you would want to do is search for the subject in a subsearch, then pass a list of MIDs to the main search, so that you can see all of the events associated with that particular subject. This search should work, even if you aren't extracting the Ironport fields. You need to replace sourcetype=ironport with whatever search terms you use to find your ironport logs (maybe a different sourcetype, or index, etc), and replace the My Subject with the keywords from your subject in the subsearch.

sourcetype=ironport [search sourcetype=ironport My Subject | rex "MID\s(?<MID>\d+)" | dedup MID | fields MID | rename MID AS query | format] | rex "MID\s(?<MID>\d+)" | rex "Subject\s(?<subject>.*)" | rex "To:\s\<(?<recipient>[^\>]+)" | rex "From:\s\<(?<sender>[^\>]+)" | stats values(sender) AS Sender values(recipient) AS recipient values(subject) AS Subject by MID

If you search your Ironport data, and you do have fields extracted already (like subect, to, from, etc.). Then you can still use the above search. Just exclude the rex statements and substitute in your field names. If you don't have the fields extracted already, I recommend you look at deploying the add-on for ESA (Ironport) as it will include field extractions so you don't have to create them yourself.

https://splunkbase.splunk.com/app/1761/#/overview

0 Karma

rockyrc
New Member

I am searching for all emails within different timeframes not specific to any subject at the moment. I am not sure if they have field extractions setup for the ironport logs, I will have to check on this. I just need to perform a search if possible with the current setup, to show the: Sender, Recipient, Subject, Message..etc. Thanks for the help.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...