Splunk Search

XOR decode search results?

New Member

Does anyone know a way to XOR results with a given key? By that I mean my search results would have an encoded hex string that I want to decode with, for example, "FF" resulting in the decoded string.

I thought there would be an easy way but i'm not seeing it.

Tags (1)
0 Karma


Yes, you can use the following app - https://splunkbase.splunk.com/app/2655/

Disclaimer: I'm the author.


0 Karma


There is no such built-in function or operator. What you can do is build your own command that you can perform XOR on your search results with.

0 Karma

Splunk Employee
Splunk Employee

Although this is technically 3.x only, this might give you a start: http://splunkbase.splunk.com/apps/Search_Commands/3.x/Technologies/Splunk/app:hexdec

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!