All Apps and Add-ons

how to decode mime header coming in event in cisco-esa mail logs?

sample event :
Thu Jan 21 14:45:07 2018 Info: MID 252525 Subject '=?windows-874?B?IFl1YW50YSBSZXNlYXJjaCi6t8fU4KTD0tDL7LvD0KjTx9G5KSA6IDcv?=\r\n\t=?windows-874?B?MTIvMjAxNyA4OjM1OjIwIEFN?=
'

I need subject to be decoded and displayed as below in field value of splunk OR subject should be changed in event while indexing.
Yuanta Research(บทวิเคราะห์ประจำวัน) : 7/\r\n\t12/2017 8:35:20 AM

Loves-to-Learn

you can use the app MIME Decoder Add-on for Cisco ESA  to decode mime header 🙂   .But I can't solve it with encoding "gbk"

0 Karma

New Member

Hi Chinmaysolanki21,

Were you able to solve this issue. I have same issue pls.
Thanks

0 Karma