Security

Best way to decrypt a logfile after its been forwarded via syslog and indexed?

dcascione
Explorer

I have a logfile that contains an encrypted section. I have the cipher key and am wondering whats the best way to decrypt the content after its already been forwarded and indexed? Thanks!

0 Karma

mattymo
Splunk Employee
Splunk Employee

Check out the encrypt/decrypt data app.

https://splunkbase.splunk.com/app/282/

It will provide you an example of how you could implement a custom command that uses your key to decrypt the data.

At the end of the day, the solution would be a custom search command.

https://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutcustomsearchcommands

- MattyMo
0 Karma

dcascione
Explorer

Ok - Thanks . I will download the Splunk app to our Dev server and see if it will work for us. Thanks again.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...