Splunk Search

How to decrypt the encrypted field?

bijodev1
Communicator

Hi All,

We are basically forwarding the cloudflare firewall events to Splunk, we have enabled "payload logging" to view what payload was send by the user.

Unfortunately the payload data which is forward to splunk is encrypted and we are not sure what tool to use to decrypt it.

We do hold this private keys with us, but how to decrypt that in the splunk search is the question.

We tried installing DECRYPT2 APP on Splunk but that is also of no help.

 

Has anyone come across this type of issues and how have they fixed it. Request someone to suggest how to proceed with this.

Labels (2)
0 Karma

bijodev1
Communicator

@isoutamo  sorry for the late response.

I am not sure on that part, I guess they use this -  "hybrid public key Encryption". I did install Decrypt2 on Splunk but not sure how that works. 

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

This is how it works with b64 encoding

index=_internal 
| head 1
| decrypt field=splunk_server btoa()
| eval foo=decrypted
| decrypt field=foo b64()
| table splunk_server foo decrypted

You must remember that it use field decrypted as output and it didn't change the original field.

Here is what functions it support https://splunkbase.splunk.com/app/5565 (Tab Details). 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

how that field has encrypted? Base64 or some other method?

I have used decrypt2 earlier without any issues with this kind of data. If I recall right it creates another field where it decrypt this field? It leave original field encrypted.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...