<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic encrypt/decrypt fields stored in index in Security</title>
    <link>https://community.splunk.com/t5/Security/encrypt-decrypt-fields-stored-in-index/m-p/22412#M760</link>
    <description>&lt;P&gt;I would like to have an option to encrypt/hash certain fields of a specific sourcetype in an index. I would prefer to not use an encrypted fileystem at this time, since this is not a supported option internally. I have a requirement to have specific fields encrypted when stored on disk or in a DB. &lt;/P&gt;

&lt;P&gt;I understand that I can mask values at index or search time, but neither of these options meets my requirements. Any suggestions? Is this option a planned enhancement? &lt;/P&gt;</description>
    <pubDate>Fri, 07 Jan 2011 08:06:21 GMT</pubDate>
    <dc:creator>lisaac</dc:creator>
    <dc:date>2011-01-07T08:06:21Z</dc:date>
    <item>
      <title>encrypt/decrypt fields stored in index</title>
      <link>https://community.splunk.com/t5/Security/encrypt-decrypt-fields-stored-in-index/m-p/22412#M760</link>
      <description>&lt;P&gt;I would like to have an option to encrypt/hash certain fields of a specific sourcetype in an index. I would prefer to not use an encrypted fileystem at this time, since this is not a supported option internally. I have a requirement to have specific fields encrypted when stored on disk or in a DB. &lt;/P&gt;

&lt;P&gt;I understand that I can mask values at index or search time, but neither of these options meets my requirements. Any suggestions? Is this option a planned enhancement? &lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2011 08:06:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/encrypt-decrypt-fields-stored-in-index/m-p/22412#M760</guid>
      <dc:creator>lisaac</dc:creator>
      <dc:date>2011-01-07T08:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: encrypt/decrypt fields stored in index</title>
      <link>https://community.splunk.com/t5/Security/encrypt-decrypt-fields-stored-in-index/m-p/22413#M761</link>
      <description>&lt;P&gt;There isn't a native mechanism for that, at least as of 4.1.&lt;/P&gt;

&lt;P&gt;Your best approaches are to either use a scripted input to read the data, or to have an external script pre-process the log files before moving them into a directory monitored by Splunk.&lt;/P&gt;

&lt;P&gt;You might also want to submit an enhancement request:
&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;A href="http://answers.splunk.com/questions/4844/how-can-i-submit-an-enhancement-request" rel="nofollow"&gt;http://answers.splunk.com/questions/4844/how-can-i-submit-an-enhancement-request&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2011 10:31:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/encrypt-decrypt-fields-stored-in-index/m-p/22413#M761</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2011-01-07T10:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: encrypt/decrypt fields stored in index</title>
      <link>https://community.splunk.com/t5/Security/encrypt-decrypt-fields-stored-in-index/m-p/22414#M762</link>
      <description>&lt;P&gt;You may want to download this add-on. It provides a pre-processor to encrypt a file's data based on your regex before it is indexed and a decrypt command to decrypt the field at search time provided you also give it the same unique key you used with the encryption. It uses DES.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunkbase.splunk.com/apps/All/4.x/app:Encrypt+and+Decrypt+data+within+Events" rel="nofollow"&gt;http://splunkbase.splunk.com/apps/All/4.x/app:Encrypt+and+Decrypt+data+within+Events&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2011 04:01:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/encrypt-decrypt-fields-stored-in-index/m-p/22414#M762</guid>
      <dc:creator>ndoshi</dc:creator>
      <dc:date>2011-03-23T04:01:01Z</dc:date>
    </item>
  </channel>
</rss>

