Using Splunk Enterprise you wouldnt be able to do this if you're ingesting through the typical mechanisms. The only thing that I can think of that would allow you to do this is using Splunk Data Stream Processor (DSP) - which allows you to create custom functions to apply to data streams and could be used for encryption/masking etc. https://docs.splunk.com/Documentation/DSP/1.1.0/User/PluginSDK
... View more