All Apps and Add-ons

How to decrypt data encrypted by third-party software?

biljanab
New Member

Hi,

We have columns on DB which are encrypted using standard encryption algorithm and key.
Encryption of data is done using third-party software.
Now when we connect to DB using Splunk we see encrypted data (Non-Displayable Column Type varbinary).
We would like to see decrypted data and to be able search, create dashboard, use all Spunk features on decrypted data.
Algorithm and key should be available to Splunk.
Is there a way to do decryption data on the flight and to display plain (decrypted) data to user?
What would you suggest as best practice?

Thanks,
Biljana

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I'm pretty sure DB Connect can't do that.
I'd write a modular input that accepts the algorithm and key as parameters, reads and decrypts the data, and gives the plain-text results to Splunk.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm pretty sure DB Connect can't do that.
I'd write a modular input that accepts the algorithm and key as parameters, reads and decrypts the data, and gives the plain-text results to Splunk.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...