Splunk Search

Creating new fields using already set data

leagawa
New Member

I am working with data from an application but the data has been forwarded to Splunk as raw data and appear randomly in various sections of the raw data. The data has no field attribute in them at all that can allow me to regex the data ( I am still not skilled in regex to that level)
My objective is to create new fields that are searchable using the following already set data

• Unexpected properties received in HTTP request
• XML received in post data for web node requestor
• Attempt to execute a rule failed in web node environment
• Attempt to run a stream from URL failed in web node environment
• A Thread name in a URL contains invalid characters
• Attempt to attack a user session has been blocked
• A rule could not be executed because Rule Security Mode is in WARN or DENY and this rule was not implicitly allowed
• Cross Site Request Forgery attack detected and was blocked
• A browser has reported a violation of your application's Content Security Policy
• SECU0010 -Â SQL functions that generate SQL sub-queries are not allowed on classes with access control policies
• Custom SQL in an RDB method must use class directives and not table names when Policy Condition rules have been defined to enforce row-level security when Viewing Instances
• Access control policies cannot be enforced in SQL INSERT and MERGE statements
• Unauthorized access for user session termination API
• A node-level data page has been loaded referencing a class with access control policies in force

any help will be appreciated

Tags (1)
0 Karma

tiagofbmm
Influencer

Can you please put a sample of your data so it is possible to work on the regex?

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...