All Apps and Add-ons

How to decrypt data encrypted by third-party software?

biljanab
New Member

Hi,

We have columns on DB which are encrypted using standard encryption algorithm and key.
Encryption of data is done using third-party software.
Now when we connect to DB using Splunk we see encrypted data (Non-Displayable Column Type varbinary).
We would like to see decrypted data and to be able search, create dashboard, use all Spunk features on decrypted data.
Algorithm and key should be available to Splunk.
Is there a way to do decryption data on the flight and to display plain (decrypted) data to user?
What would you suggest as best practice?

Thanks,
Biljana

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I'm pretty sure DB Connect can't do that.
I'd write a modular input that accepts the algorithm and key as parameters, reads and decrypts the data, and gives the plain-text results to Splunk.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm pretty sure DB Connect can't do that.
I'd write a modular input that accepts the algorithm and key as parameters, reads and decrypts the data, and gives the plain-text results to Splunk.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...