Sometimes malicious indicators are buried inside long, messy payload strings that Splunk hasn't parsed automatically.
You can use the `rex` command (Regular Expression Extraction) to create a new field out of almost anything on the fly during your investigation.