I have a logfile that contains an encrypted section. I have the cipher key and am wondering whats the best way to decrypt the content after its already been forwarded and indexed? Thanks!
Check out the encrypt/decrypt data app.
https://splunkbase.splunk.com/app/282/
It will provide you an example of how you could implement a custom command that uses your key to decrypt the data.
At the end of the day, the solution would be a custom search command.
https://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutcustomsearchcommands
Ok - Thanks . I will download the Splunk app to our Dev server and see if it will work for us. Thanks again.