Splunk Search

Decode base64 into any charset

antoniolamonica
SplunkTrust
SplunkTrust

Is there a command or app that will decode base64 and detect the correct charset to output to?

Currently, I'm currently unable to decode to UTF-16LE.
Splunk wants to decode UTF-8. 

In my current role, I cannot edit any .conf files.
Those are administrated by a server team. 

If there is an app, I can request it be installed, else I'm working solely out of the SPL. 

Labels (4)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

There are couple of apps which can manage e.g. base64 encoding. Here is one which I have used https://splunkbase.splunk.com/app/5565

When you have issues with windows character sets, you must add character set information into UF’s props.conf. There are some examples in community and this is also described on docs.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...