Hello splunkers,
I've got PEM encoded value from SSL certificates that are already indexed.
I've made a python custom search command to display a decoded part of my value : the "not before" date of my x509 certificate.
The extraction works through the search command, but i couldn't manage to make it work through a conf file.
Could anyone help me through this.
Thank you.
↧