Hi Team,
Is there any way to decode the logs which is already onboarded into splunk. Do we have any app to decode.?
Please suggest @ITWhisperer
By "decode" do you mean view the logs in their original form rather than parsed fields? If so, the answer is yes, that data is stored in the _raw field.
Yo could try e.g.
<your base search>
| table _time _raw
r. Ismo