Splunk Search

Creating new fields using already set data

leagawa
New Member

I am working with data from an application but the data has been forwarded to Splunk as raw data and appear randomly in various sections of the raw data. The data has no field attribute in them at all that can allow me to regex the data ( I am still not skilled in regex to that level)
My objective is to create new fields that are searchable using the following already set data

• Unexpected properties received in HTTP request
• XML received in post data for web node requestor
• Attempt to execute a rule failed in web node environment
• Attempt to run a stream from URL failed in web node environment
• A Thread name in a URL contains invalid characters
• Attempt to attack a user session has been blocked
• A rule could not be executed because Rule Security Mode is in WARN or DENY and this rule was not implicitly allowed
• Cross Site Request Forgery attack detected and was blocked
• A browser has reported a violation of your application's Content Security Policy
• SECU0010 -Â SQL functions that generate SQL sub-queries are not allowed on classes with access control policies
• Custom SQL in an RDB method must use class directives and not table names when Policy Condition rules have been defined to enforce row-level security when Viewing Instances
• Access control policies cannot be enforced in SQL INSERT and MERGE statements
• Unauthorized access for user session termination API
• A node-level data page has been loaded referencing a class with access control policies in force

any help will be appreciated

Tags (1)
0 Karma

tiagofbmm
Influencer

Can you please put a sample of your data so it is possible to work on the regex?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...