How do you perform a field extraction on the fly in Splunk?
This should help you out: http://www.splunk.com/base/Documentation/latest/User/ExtractNewFields