Subsearch

Let's start with these events:

2015-02-10 12:59:59 msgid=704783 from=tuck@companyx.com to=taylor@VENDOR1.com 
2015-02-10 12:59:59 msgid=171755 from=steve@companyx.com to=lou@VENDOR1.com 
2015-02-10 12:59:59 msgid=668955 from=lou@companyx.com to=steve@Vendor2.com 
2015-02-10 12:59:59 msgid=001404 from=mary@companyx.com to=richard@Vendor2.com 
2015-02-10 12:59:59 msgid=284794 from=ronnie@companyx.com to=toto@Vendor2.com 
2015-02-10 12:59:59 msgid=362127 from=nanette@companyx.com to=sam@Vendor2.com 
2015-02-10 12:59:59 msgid=571419 from=paige@companyx.com to=ronnie@g&r.com 

From these events, let's find out to whom mary has sent messages. In these events, we see that the from and to values are in different entries. We can use stats to pull ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.