All Apps and Add-ons

How to decrypt data encrypted by third-party software?

biljanab
New Member

Hi,

We have columns on DB which are encrypted using standard encryption algorithm and key.
Encryption of data is done using third-party software.
Now when we connect to DB using Splunk we see encrypted data (Non-Displayable Column Type varbinary).
We would like to see decrypted data and to be able search, create dashboard, use all Spunk features on decrypted data.
Algorithm and key should be available to Splunk.
Is there a way to do decryption data on the flight and to display plain (decrypted) data to user?
What would you suggest as best practice?

Thanks,
Biljana

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I'm pretty sure DB Connect can't do that.
I'd write a modular input that accepts the algorithm and key as parameters, reads and decrypts the data, and gives the plain-text results to Splunk.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm pretty sure DB Connect can't do that.
I'd write a modular input that accepts the algorithm and key as parameters, reads and decrypts the data, and gives the plain-text results to Splunk.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...