<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk show-decrypted command usage in Security</title>
    <link>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/656298#M17248</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I'm Vatsal from the Community Moderator team. As I can see you answered your own question. In such scenario if you accept your own answer it will be very useful for future visitors here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Happy Splunking!!!&lt;/P&gt;</description>
    <pubDate>Thu, 31 Aug 2023 16:11:09 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2023-08-31T16:11:09Z</dc:date>
    <item>
      <title>splunk show-decrypted command usage</title>
      <link>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/655797#M17233</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;&lt;P&gt;I am used to use the following command&amp;nbsp;to decrypt $7 Splunk configuration password such as&amp;nbsp;pass4SymmKey or&amp;nbsp;sslConfig.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk show-decrypted --value '&amp;lt;encrypted_value&amp;gt;'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have several questions regarding this command :&amp;nbsp;&lt;/P&gt;&lt;P&gt;1/ Do you ever find any official documentation about it ? I was&amp;nbsp; looking here but not result :&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.0/Admin/CLIadmincommands" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.0/Admin/CLIadmincommands&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2/ Is it possible to use this command for $6 encrypted (hased ?) string, like the one stored for admin password stored in $SPLUNK_HOME/etc/passwd. I suppose it's not possible since it's a password and it should not be "reversible" for security reason.&lt;/P&gt;&lt;P&gt;3/ This question is related to the previous one. Is it right to say that $7 value has been &lt;STRONG&gt;encrypted&lt;/STRONG&gt; since it's possible to revert it and $6 has been &lt;STRONG&gt;hashed&lt;/STRONG&gt; because it's impossible to get the clear value back ?&lt;/P&gt;&lt;P&gt;Thanks for your help !&lt;BR /&gt;GaetanVP&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 09:27:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/655797#M17233</guid>
      <dc:creator>GaetanVP</dc:creator>
      <dc:date>2023-08-28T09:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: splunk show-decrypted command usage</title>
      <link>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/655798#M17234</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sincerely, it's the first time I see this command!&lt;/P&gt;&lt;P&gt;Anyway, here you can find more infos&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378993" target="_blank"&gt;https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378993&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 09:35:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/655798#M17234</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-08-28T09:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: splunk show-decrypted command usage</title>
      <link>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/656272#M17247</link>
      <description>&lt;P&gt;Hello all and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just for information I contacted Splunk support for that, here are some information :&amp;nbsp;&lt;/P&gt;&lt;P&gt;1/ Indeed there are no official documentation about that command, apparently for security reason... Let's say it is security through obscurity (and I am not a fan of that concept).&amp;nbsp;&lt;/P&gt;&lt;P&gt;2/&amp;nbsp; As assumed, it is impossible to revert a $6 value since it has been hashed by a SHA-512 algorithm *just like UNIX based /etc/shadow file). But you can revert $7 value if you have the correct splunk.secret value.&lt;/P&gt;&lt;P&gt;3/ Yes&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;GaetanVP&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 13:41:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/656272#M17247</guid>
      <dc:creator>GaetanVP</dc:creator>
      <dc:date>2023-08-31T13:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: splunk show-decrypted command usage</title>
      <link>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/656298#M17248</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I'm Vatsal from the Community Moderator team. As I can see you answered your own question. In such scenario if you accept your own answer it will be very useful for future visitors here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Happy Splunking!!!&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 16:11:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/656298#M17248</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2023-08-31T16:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: splunk show-decrypted command usage</title>
      <link>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/656336#M17250</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;let us know if we can help you more, or, please, accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 21:23:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/656336#M17250</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-08-31T21:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: splunk show-decrypted command usage</title>
      <link>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/656369#M17251</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;it's really weird that this and couple of other are not documented here. Maybe it's good to ask that from doc team? If I recall right those has "published" 7.3 (or 7.2 version)?&lt;/P&gt;&lt;P&gt;At least these are there also without mention on that doc pages:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;splunk show-encrypted --value 'changeme'&lt;/LI&gt;&lt;LI&gt;splunk hash-passwd changeme&lt;/LI&gt;&lt;LI&gt;splunk gen-random-passwd&lt;/LI&gt;&lt;LI&gt;splunk gen-cc-splunk-secret (see:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.0/CommonCriteria/Commoncriteriainstallationandconfigurationoverview" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.0/CommonCriteria/Commoncriteriainstallationandconfigurationoverview&lt;/A&gt;)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Probably there are some other undocumented commands too.&lt;/P&gt;&lt;P&gt;Some of those are used e.g. splunk-ansible scripts and there are other documentation on net by someone else than Splunk.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 06:58:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/656369#M17251</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-09-01T06:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: splunk show-decrypted command usage</title>
      <link>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/656618#M17264</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 07:25:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-show-decrypted-command-usage/m-p/656618#M17264</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-05T07:25:48Z</dc:date>
    </item>
  </channel>
</rss>

