I have installed base64 splunk app for decoding base64 filed but didn't decode the logs, I have used
|base64 field=myfiled action=decode mode=replace suppress_error=True
Is there anyone who has used this app and was able to decode it? Thanks for any feedback.
Dan
Looking at how the script works, I think you want to run it like this:
| base64 action=decode myfield1 myfield2 myfield3 ... myfieldN