Security

Is there a Splunk command to decrypt encrypted values under domain field?

VijaySrrie
Builder

Hi All,

I have encrypted the user field with sha256 

index=abc   sourcetype=xyz
| eval domain = sha256(User)
| table  domain

I am able to see encrypted values under domain field

Is there a splunk command to decrypt it?

Labels (1)
Tags (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

Encryption and hashing are different things - you are not "encrypting" data, you are just creating a hash of the data (User) 

https://en.wikipedia.org/wiki/Hash_function

For example, if you think that A=1, B=2 etc, then a "hash" of the word "HELLO" could be 52 (8+5+12+12+15)

But you cannot reverse 52 to make the word "HELLO" again - 52 could equally be ZZ or 52 letter A

 

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Encryption and hashing are different things - you are not "encrypting" data, you are just creating a hash of the data (User) 

https://en.wikipedia.org/wiki/Hash_function

For example, if you think that A=1, B=2 etc, then a "hash" of the word "HELLO" could be 52 (8+5+12+12+15)

But you cannot reverse 52 to make the word "HELLO" again - 52 could equally be ZZ or 52 letter A

 

0 Karma

yuanliu
SplunkTrust
SplunkTrust

sha256 is a hash function, meaning that you cannot "decrypt" the output.  It would have a profound impact in data security if anyone finds a way to reverse the output. (sha1 has been known to be insufficient for years but it wasn't until rather recently when Google managed to create a collision using their very powerful TPUs.  Even then, it wasn't to decrypt the hash value; the only attack mode to a hash function is hoping to find a string that will produce the same hash value.  There is no way to know whether the collision value is the original value.)

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...