# .opendistro\_security record encoding

**URL:** <https://forum.opensearch.org/t/opendistro-security-record-encoding/8436>\
**Category:** Security\
**Tags:** discuss\
**Created:** [January 27, 2022, 12:06pm UTC](https://forum.opensearch.org/t/opendistro-security-record-encoding/8436 "2022-01-27T12:06:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rlevitsky](https://avatars.discourse-cdn.com/v4/letter/r/49beb7/32.png) [@rlevitsky](https://forum.opensearch.org/u/rlevitsky)\
**Post date:** [January 27, 2022, 12:06pm UTC](https://forum.opensearch.org/t/opendistro-security-record-encoding/8436/1 "2022-01-27T12:06:14Z")

</div>

Dear All,  
While working on the broken Kibana issue ([Kibana stopped working after upgrade Opendistro 1.10.2 to 1.13.3 - #7 by rlevitsky](https://forum.opensearch.org/t/kibana-stopped-working-after-upgrade-opendistro-1-10-2-to-1-13-3/8077/7)),  
I am trying to identify the exact content of the .opendistro\_security index.  
Fetching the “[https://v161:9200/.opendistro\_security/\_search?pretty=true&q=\*:](https://v161:9200/.opendistro_security/_search?pretty=true&q=*:)\*”,  
I see that content is encoded, say,

```auto
      {
        "_index" : ".opendistro_security",
        "_type" : "_doc",
        "_id" : "whitelist",
        "_score" : 1.0,
        "_source" : {
          "whitelist" : "eyJfbWV0YSI6eyJ0eXBlIjoid2hpdGVsaXN0IiwiY29uZmlnX3ZlcnNpb24iOjJ9LCJjb25maWciOnsiZW5hYmxlZCI6ZmFsc2UsInJlcXVlc3RzIjp7Ii9fY2x1c3Rlci9zZXR0aW5ncyI6WyJHRVQiXSwiL19jYXQvbm9kZXMiOlsiR0VUIl19fX0="
        }
      }

```

Could you please advise me how can I decode the content of the data field to the human-readable form?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Anthony](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/anthony/32/9939_2.png) [@Anthony](https://forum.opensearch.org/u/Anthony)\
**Post date:** [January 27, 2022, 12:08pm UTC](https://forum.opensearch.org/t/opendistro-security-record-encoding/8436/2 "2022-01-27T12:08:40Z")

</div>

@rlevitsky That’s just base64 encoded, any base64 decoder should work.

---

<div class="post-metadata">

**Author:** ![rlevitsky](https://avatars.discourse-cdn.com/v4/letter/r/49beb7/32.png) [@rlevitsky](https://forum.opensearch.org/u/rlevitsky)\
**Post date:** [January 27, 2022, 12:19pm UTC](https://forum.opensearch.org/t/opendistro-security-record-encoding/8436/3 "2022-01-27T12:19:14Z")

</div>

Thank you so much Anthony, I guessed it too and it works.  
This doesn’t seems to be helping to solve my original “no index pattern” issue - the content so far seems to be the same as the configuration files…
