Splunk Search

Anybody have an idea for base64 decoding of fields in Splunk 6.5

las
Contributor

Hi.

I have upgraded to Splunk 6.5, and have a new source, with some base64 encoded values.
I have tried looking at the varios add-ons, I could find, but none of them seems to support Splunk6.5.

Any ideas are welcome.

Thanks.

1 Solution

rjthibod
Champion

I don't think there is any other option (right now) than building your own command if you can't use an existing add-on/app.

Note, many times an add-on or an app built for 6.2 or 6.3 will actually work on 6.5 - the author hasn't tested or indicated as such on Splunkbase.

Regardless, looking at either of the two old apps/add-ons may be an opportunity for you to learn the ins and outs of building your own SPL commands.

View solution in original post

AVOLLMER
Explorer

I built a macro to convert base64 fields and append them to your search results since I wasn't able to install apps with my privileges.
https://answers.splunk.com/answers/35521/base64-decoding-in-search.html

0 Karma

rjthibod
Champion

I don't think there is any other option (right now) than building your own command if you can't use an existing add-on/app.

Note, many times an add-on or an app built for 6.2 or 6.3 will actually work on 6.5 - the author hasn't tested or indicated as such on Splunkbase.

Regardless, looking at either of the two old apps/add-ons may be an opportunity for you to learn the ins and outs of building your own SPL commands.

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...