Splunk Search

Decode base64 into any charset

antoniolamonica
SplunkTrust
SplunkTrust

Is there a command or app that will decode base64 and detect the correct charset to output to?

Currently, I'm currently unable to decode to UTF-16LE.
Splunk wants to decode UTF-8. 

In my current role, I cannot edit any .conf files.
Those are administrated by a server team. 

If there is an app, I can request it be installed, else I'm working solely out of the SPL. 

Labels (4)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

There are couple of apps which can manage e.g. base64 encoding. Here is one which I have used https://splunkbase.splunk.com/app/5565

When you have issues with windows character sets, you must add character set information into UF’s props.conf. There are some examples in community and this is also described on docs.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...