How to write search query to find from particular host is sending any credit card data into splunk by using regex ?
Discover card
dinerclub
mastercard
visa
index=* host =X|regex="(4[0-9]{14})|(5[1-5][0-9]{14})
Please help me in query
You can use the regex used in below link. https://wiki.splunk.com/Community:Credit_card_masking_regex
The filtering query can be like this
index=* host =X|regex _raw=">+REGEXfromABOVElink"
OR
index=* host =X|where match(_raw,"REGEXfromABOVElink")
Thanks Somesoni2