<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Masking in Security</title>
    <link>https://community.splunk.com/t5/Security/Data-Masking/m-p/667163#M17356</link>
    <description>Hi&lt;BR /&gt;With recent Splunk versions there are also Ingest Actions and if you have any Splunk Cloud instance then you could use Splunk Edge Processor as a one excellent option.&lt;BR /&gt;r. Ismo</description>
    <pubDate>Thu, 02 Nov 2023 11:51:28 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2023-11-02T11:51:28Z</dc:date>
    <item>
      <title>Data Masking</title>
      <link>https://community.splunk.com/t5/Security/Data-Masking/m-p/667151#M17354</link>
      <description>&lt;P&gt;Kindly help on how to mask the password present in the field "securityToken"&amp;nbsp; in the IIS logs. Sample event for reference.&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;2023-11-02 06:53:00 xx.xxx.xxx.xx GET /Security/Security/Logon 123 - xx.xxx.x.xxx Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.198+Safari/537.36 https://abc.xyz.bcd.com/security/security/ChangePasswordWithQuestions?userName=xyz@abc.com&amp;amp;&lt;U&gt;&lt;STRONG&gt;securityToken=xxxxxxxx&lt;/STRONG&gt;&lt;/U&gt;&amp;nbsp; 200 0 0 14&lt;/P&gt;&lt;P data-unlink="true"&gt;2023-11-02 06:52:25 xx.xxx.xxx.xx GET / 111 - xx.xxx.x.xxx Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+HeadlessChrome/117.0.5938.88+Safari/537.36 https://abc.xyz.bnm.com/security/security/ChangePasswordWithQuestions?userName=xyz@abc.com&amp;amp;&lt;U&gt;&lt;STRONG&gt;securityToken=xxxxxxxx&lt;/STRONG&gt;&lt;/U&gt;&amp;nbsp; 302 0 0 0&lt;/P&gt;&lt;P&gt;We are in Splunk Cloud and can we able to mask the password in GUI itself or should i need to move the output&amp;nbsp; of the client machines to the HF server and then place the props and transforms to mask the password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly help to check and update on the same.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 11:16:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Masking/m-p/667151#M17354</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2023-11-02T11:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: Data Masking</title>
      <link>https://community.splunk.com/t5/Security/Data-Masking/m-p/667158#M17355</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have two solutions:&lt;/P&gt;&lt;P&gt;SEDCMD in props.conf (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata?_gl=1*mf7xvx*_ga*MTY1NjIzMDM3OC4xNjk3MjA1MzU0*_ga_GS7YF8S63Y*MTY5ODkyMDExMS40OTMuMS4xNjk4OTI0MDg4LjYwLjAuMA..*_ga_5EPM2P39FV*MTY5ODkyMDA2Ni42MDcuMS4xNjk4OTI0MjIxLjAuMC4w&amp;amp;_ga=2.60123688.468842275.1697205354-1656230378.1697205354&amp;amp;_gac=1.124697080.1697439287.Cj0KCQjwm66pBhDQARIsALIR2zDDpMo42f4nQY5ylRFnUfEyW_h0bbBBKVDgM2rBU1cuYdYxGqfUTWkaAjkxEALw_wcB#Anonymize_data_with_a_sed_script" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata?_gl=1*mf7xvx*_ga*MTY1NjIzMDM3OC4xNjk3MjA1MzU0*_ga_GS7YF8S63Y*MTY5ODkyMDExMS40OTMuMS4xNjk4OTI0MDg4LjYwLjAuMA..*_ga_5EPM2P39FV*MTY5ODkyMDA2Ni42MDcuMS4xNjk4OTI0MjIxLjAuMC4w&amp;amp;_ga=2.60123688.468842275.1697205354-1656230378.1697205354&amp;amp;_gac=1.124697080.1697439287.Cj0KCQjwm66pBhDQARIsALIR2zDDpMo42f4nQY5ylRFnUfEyW_h0bbBBKVDgM2rBU1cuYdYxGqfUTWkaAjkxEALw_wcB#Anonymize_data_with_a_sed_script&lt;/A&gt;)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[your_sourcetype]
SEDCMD-mask = s/securityToken=[^ ]*/securityToken=********/g&lt;/LI-CODE&gt;&lt;P&gt;or using props.conf and transforms.conf /&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata?_gl=1*mf7xvx*_ga*MTY1NjIzMDM3OC4xNjk3MjA1MzU0*_ga_GS7YF8S63Y*MTY5ODkyMDExMS40OTMuMS4xNjk4OTI0MDg4LjYwLjAuMA..*_ga_5EPM2P39FV*MTY5ODkyMDA2Ni42MDcuMS4xNjk4OTI0MjIxLjAuMC4w&amp;amp;_ga=2.60123688.468842275.1697205354-1656230378.1697205354&amp;amp;_gac=1.124697080.1697439287.Cj0KCQjwm66pBhDQARIsALIR2zDDpMo42f4nQY5ylRFnUfEyW_h0bbBBKVDgM2rBU1cuYdYxGqfUTWkaAjkxEALw_wcB#Configure_the_transforms.conf_file" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata?_gl=1*mf7xvx*_ga*MTY1NjIzMDM3OC4xNjk3MjA1MzU0*_ga_GS7YF8S63Y*MTY5ODkyMDExMS40OTMuMS4xNjk4OTI0MDg4LjYwLjAuMA..*_ga_5EPM2P39FV*MTY5ODkyMDA2Ni42MDcuMS4xNjk4OTI0MjIxLjAuMC4w&amp;amp;_ga=2.60123688.468842275.1697205354-1656230378.1697205354&amp;amp;_gac=1.124697080.1697439287.Cj0KCQjwm66pBhDQARIsALIR2zDDpMo42f4nQY5ylRFnUfEyW_h0bbBBKVDgM2rBU1cuYdYxGqfUTWkaAjkxEALw_wcB#Configure_the_transforms.conf_file&lt;/A&gt;&amp;nbsp;)&lt;/P&gt;&lt;P&gt;in props.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[your_sourcetype]
TRANSFORMS-anonymize = anonymizer&lt;/LI-CODE&gt;&lt;P&gt;in transforms.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[anonymizer]
REGEX = securityToken=([^ ]*)
FORMAT = securityToken=(*****)
DEST_KEY = _raw&lt;/LI-CODE&gt;&lt;P&gt;I prefer the first solution.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 11:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Masking/m-p/667158#M17355</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-02T11:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Data Masking</title>
      <link>https://community.splunk.com/t5/Security/Data-Masking/m-p/667163#M17356</link>
      <description>Hi&lt;BR /&gt;With recent Splunk versions there are also Ingest Actions and if you have any Splunk Cloud instance then you could use Splunk Edge Processor as a one excellent option.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Thu, 02 Nov 2023 11:51:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Masking/m-p/667163#M17356</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-02T11:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Data Masking</title>
      <link>https://community.splunk.com/t5/Security/Data-Masking/m-p/667294#M17359</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried the first solution but it didn't masked the value. I have forwarded the UF logs to the HF server and then to indexers.&lt;/P&gt;&lt;P&gt;And I have tried with the sourcetype as well as with source but it didn't worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Props.conf:&lt;/P&gt;&lt;P&gt;sourcetype:&lt;BR /&gt;[abc]&lt;BR /&gt;SEDCMD-mask = s/securityToken=[^ ]*/securityToken=********/g&lt;/P&gt;&lt;P&gt;source:&lt;BR /&gt;[source::C:\\abc\\def\\xyz\\*\\*.log]&lt;BR /&gt;SEDCMD-mask = s/securityToken=[^ ]*/securityToken=********/g&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 12:29:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Masking/m-p/667294#M17359</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2023-11-03T12:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: Data Masking</title>
      <link>https://community.splunk.com/t5/Security/Data-Masking/m-p/667296#M17360</link>
      <description>Have you put those configurations to HF? As it's the 1st full splunk instance, it will do those actions not indexer.</description>
      <pubDate>Fri, 03 Nov 2023 12:36:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Masking/m-p/667296#M17360</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-03T12:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: Data Masking</title>
      <link>https://community.splunk.com/t5/Security/Data-Masking/m-p/667302#M17361</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;yes i have placed the props in HF.&lt;/P&gt;&lt;P&gt;So i tried with source format as well and that too didnt worked.&lt;/P&gt;&lt;P&gt;So is the source format is correct?&lt;/P&gt;&lt;P&gt;Can we do masking based on host in props? If yes kindly let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 12:56:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Masking/m-p/667302#M17361</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2023-11-03T12:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Data Masking</title>
      <link>https://community.splunk.com/t5/Security/Data-Masking/m-p/667303#M17362</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;said, You have to put these conf files on Indexers or (if present) on Heavy Forwarders.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 13:02:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Masking/m-p/667303#M17362</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-03T13:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: Data Masking</title>
      <link>https://community.splunk.com/t5/Security/Data-Masking/m-p/667307#M17363</link>
      <description>&lt;P&gt;You can do it also based on source, but you must remember precedence!&lt;/P&gt;&lt;PRE&gt;[&amp;lt;spec&amp;gt;]
* This stanza enables properties for a given &amp;lt;spec&amp;gt;.
* A props.conf file can contain multiple stanzas for any number of
  different &amp;lt;spec&amp;gt;.
* Follow this stanza name with any number of the following setting/value
  pairs, as appropriate for what you want to do.
* If you do not set a setting for a given &amp;lt;spec&amp;gt;, the default is used.

&amp;lt;spec&amp;gt; can be:
1. &amp;lt;sourcetype&amp;gt;, the source type of an event.
2. host::&amp;lt;host&amp;gt;, where &amp;lt;host&amp;gt; is the host, or host-matching pattern, for an
                 event.
3. source::&amp;lt;source&amp;gt;, where &amp;lt;source&amp;gt; is the source, or source-matching
                     pattern, for an event.
4. rule::&amp;lt;rulename&amp;gt;, where &amp;lt;rulename&amp;gt; is a unique name of a source type
                     classification rule.
5. delayedrule::&amp;lt;rulename&amp;gt;, where &amp;lt;rulename&amp;gt; is a unique name of a delayed
                            source type classification rule.
                            These are only considered as a last resort
                            before generating a new source type based on the
                            source seen.

**[&amp;lt;spec&amp;gt;] stanza precedence:**

For settings that are specified in multiple categories of matching [&amp;lt;spec&amp;gt;]
stanzas, [host::&amp;lt;host&amp;gt;] settings override [&amp;lt;sourcetype&amp;gt;] settings.
Additionally, [source::&amp;lt;source&amp;gt;] settings override both [host::&amp;lt;host&amp;gt;]
and [&amp;lt;sourcetype&amp;gt;] settings.&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;And of course restart is needed after changing those.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also "splunk btool props list --debug" is excellent tool to check that you have correct configuration in use.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 13:29:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Data-Masking/m-p/667307#M17363</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-03T13:29:24Z</dc:date>
    </item>
  </channel>
</rss>

