Splunk Cloud Platform

How to split this string: DF - R - Emails with words (O365) sent to Personal Account (scored) (Data Exfil)?

Italy1358
Path Finder

Ciao 

Could you please help me split this string: DF - R - Emails with words (O365) sent to Personal  Account (scored) (Data Exfil) 

I need the DF - R - Emails with words 
(O365)
sent to personal account
(scored)

(data exfil)

all to be split into their own fields

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Italy1358,

yes, it should be easy, but you should share some sample of logs, highlighting the parts to extract.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...