<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: does Splunk UF has capability to mask data as it send to indexer? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682199#M113971</link>
    <description>&lt;P&gt;Would it fit your use case to set inputs.conf and outputs.conf such that the UF forwards the same logs to two different indexer servers, then those indexer servers have different props.conf which can mask and not mask the fields?&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems like props.conf on the UF won't solve your problem.&lt;/P&gt;</description>
    <pubDate>Wed, 27 Mar 2024 22:07:09 GMT</pubDate>
    <dc:creator>marnall</dc:creator>
    <dc:date>2024-03-27T22:07:09Z</dc:date>
    <item>
      <title>does Splunk UF has capability to mask data as it send to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682177#M113968</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Is it possible in Splunk to have one &lt;/SPAN&gt;props.conf&lt;SPAN&gt; file on one server's Universal Forwarder (UF) for a specific app, and another &lt;/SPAN&gt;props.conf&lt;SPAN&gt; file on a different server for the same app, but with one file masking a certain field and the other not?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 19:36:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682177#M113968</guid>
      <dc:creator>abi2023</dc:creator>
      <dc:date>2024-03-27T19:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: does Splunk UF has capability to mask data as it send to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682191#M113970</link>
      <description>&lt;P&gt;UFs are independent so it is possible to have different configurations on each.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the UFs are managed by a Deployment Server, however, you cannot have different props.conf files in the same app.&amp;nbsp; You would have to create separate apps and put them in different server classes for the UFs to have different props for the same sourcetype.&lt;/P&gt;&lt;P&gt;To answer the second part of the question, you *should* be able to put &lt;FONT face="courier new,courier"&gt;force_local_processing = true&lt;/FONT&gt; in the props.conf file to have the UF perform masking.&amp;nbsp; Of course, you would also need &lt;FONT face="courier new,courier"&gt;SEDCMD&lt;/FONT&gt; settings to define the maskings themselves.&amp;nbsp; I say "should" because I don't have experience with this and the documentation isn't clear about what the UF will do locally.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 21:34:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682191#M113970</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-03-27T21:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: does Splunk UF has capability to mask data as it send to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682199#M113971</link>
      <description>&lt;P&gt;Would it fit your use case to set inputs.conf and outputs.conf such that the UF forwards the same logs to two different indexer servers, then those indexer servers have different props.conf which can mask and not mask the fields?&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems like props.conf on the UF won't solve your problem.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 22:07:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682199#M113971</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-03-27T22:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: does Splunk UF has capability to mask data as it send to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682236#M113979</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/256053"&gt;@abi2023&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263556"&gt;@marnall&lt;/a&gt;&amp;nbsp;said, you can create different apps and deploy to the UFs using different serverclasses.&lt;/P&gt;&lt;P&gt;About data mascking, for my knowledge UFs enter only in the input phase, but the other phases (merge and parsing) are in the first full Splunk instance that data are passing through.&lt;/P&gt;&lt;P&gt;In other words, in the Indexers or (when present) in the first Heavy Forwarder, but not in the UFs.&lt;/P&gt;&lt;P&gt;If your doubt is that data are sent in clear mode, you can encrypt them between the UFs and the Indexers (or HFs), and then mask them on these other systems.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 06:35:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682236#M113979</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-03-28T06:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: does Splunk UF has capability to mask data as it send to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682389#M113988</link>
      <description>&lt;P&gt;Can I do this buy source? &amp;nbsp;and does &amp;nbsp;source can take different props conf.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2024 13:29:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682389#M113988</guid>
      <dc:creator>abi2023</dc:creator>
      <dc:date>2024-03-29T13:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: does Splunk UF has capability to mask data as it send to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682468#M113991</link>
      <description>&lt;P&gt;Yep. While the local processing on UF part is supposed to work _somehow_ it's indeed not very well docummented and not recommended.&lt;/P&gt;&lt;P&gt;If you want only some sources masked, you could use source-based or host-based stanzas in props.conf on your indexer(s) to selectively apply your SEDCMD or transform only to specific part of your data.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2024 08:24:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682468#M113991</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-03-30T08:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: does Splunk UF has capability to mask data as it send to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682508#M113996</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/256053"&gt;@abi2023&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you need to mask data pre-transit for whatever reason and the&amp;nbsp;&lt;EM&gt;force_local_processing&lt;/EM&gt;&amp;nbsp;setting doesn't meet your requirements, you can use the &lt;EM&gt;unarchive_cmd&lt;/EM&gt;&amp;nbsp;props.conf setting to stream inputs through Perl, sed, or any command or script that reads input from stdin and writes output to stdout.&lt;/P&gt;&lt;P&gt;For example, to mask strings that might be IPv4 addresses in a log file using Perl:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;/tmp/foo.log&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;This is 1.2.3.4.
Uh oh, 5.6.7.8 here.
Definitely not an IP address: a.1.b.4.
512.0.1.2 isn't an IP address. Oops.&lt;/LI-CODE&gt;&lt;P&gt;&lt;STRONG&gt;inputs.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;[monitor:///tmp/foo.log]
sourcetype = foo&lt;/LI-CODE&gt;&lt;P&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;[source::/tmp/foo.log]
unarchive_cmd = perl -pe 's/[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}/*.*.*.*/'
sourcetype = preprocess-foo
NO_BINARY_CHECK = tru

[preprocess-foo]
invalid_cause = archive
is_valid = False
LEARN_MODEL = false

[foo]
DATETIME_CONFIG = NONE
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
EVENT_BREAKER_ENABLE = true
EVENT_BREAKER = ([\r\n]+)&lt;/LI-CODE&gt;&lt;P&gt;The transmitted events will be masked before they're sent to the receiver:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tscroggins_0-1711857184100.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29974i18C64C2806F16C82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tscroggins_0-1711857184100.png" alt="tscroggins_0-1711857184100.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regular expressions that work with SEDCMD should work with Perl without modifications.&lt;/P&gt;&lt;P&gt;The &lt;EM&gt;unarchive_cmd&lt;/EM&gt;&amp;nbsp;setting is a flexible alternative to scripted and modular inputs. The sources do not have to be archive files.&lt;/P&gt;&lt;P&gt;As others have noted, you can deploy different props.conf configurations to different forwarders. Your props.conf settings for line breaks, timestamp extraction, etc., should be deployed to the next downstream instance of Splunk Enterprise (heavy forwarder or indexer) or Splunk Cloud.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2024 03:58:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682508#M113996</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2024-03-31T03:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: does Splunk UF has capability to mask data as it send to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682509#M113997</link>
      <description>&lt;P&gt;My previous answer used a single source example, but you can modify unarchive_cmd settings per-source as needed.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2024 03:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682509#M113997</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2024-03-31T03:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: does Splunk UF has capability to mask data as it send to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682510#M113998</link>
      <description>&lt;P&gt;Small correction:&lt;/P&gt;&lt;P&gt;NO_BINARY_CHECK = tru&lt;EM&gt;e&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;(If I edit my original answer, the formatting will be mangled.)&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2024 04:05:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/does-Splunk-UF-has-capability-to-mask-data-as-it-send-to-indexer/m-p/682510#M113998</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2024-03-31T04:05:16Z</dc:date>
    </item>
  </channel>
</rss>

