<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Redact syslog using Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Redact-syslog-using-Splunk/m-p/126342#M25997</link>
    <description>&lt;P&gt;What we are trying to do is pipe DLP incident data to Splunk using syslog. However the challenge is that we need to redact certain data fields from the DLP syslog output (can't limit this on DLP's side). So I was wondering if it's possible to have another Splunk instance sit between the DLP and the existing indexing Splunk infrastructure, and which will redact/mask specific data  from the syslog before forwarding it to the indexing Splunk. If not, is there any other way to archive this? &lt;/P&gt;

&lt;P&gt;Thank you for any help&lt;/P&gt;</description>
    <pubDate>Wed, 09 Apr 2014 20:54:41 GMT</pubDate>
    <dc:creator>zerolife</dc:creator>
    <dc:date>2014-04-09T20:54:41Z</dc:date>
    <item>
      <title>Redact syslog using Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Redact-syslog-using-Splunk/m-p/126342#M25997</link>
      <description>&lt;P&gt;What we are trying to do is pipe DLP incident data to Splunk using syslog. However the challenge is that we need to redact certain data fields from the DLP syslog output (can't limit this on DLP's side). So I was wondering if it's possible to have another Splunk instance sit between the DLP and the existing indexing Splunk infrastructure, and which will redact/mask specific data  from the syslog before forwarding it to the indexing Splunk. If not, is there any other way to archive this? &lt;/P&gt;

&lt;P&gt;Thank you for any help&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 20:54:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Redact-syslog-using-Splunk/m-p/126342#M25997</guid>
      <dc:creator>zerolife</dc:creator>
      <dc:date>2014-04-09T20:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Redact syslog using Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Redact-syslog-using-Splunk/m-p/126343#M25998</link>
      <description>&lt;P&gt;Yes you can do this.  If you are collecting using a heavy forwarder to either read the log files you can do it there or with an intermediate forwarder.  It needs to be the first Splunk Enterprise system that cooks the data.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.2/Data/Anonymizedatausingconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.2/Data/Anonymizedatausingconfigurationfiles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 21:50:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Redact-syslog-using-Splunk/m-p/126343#M25998</guid>
      <dc:creator>jgedeon120</dc:creator>
      <dc:date>2014-04-09T21:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: Redact syslog using Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Redact-syslog-using-Splunk/m-p/126344#M25999</link>
      <description>&lt;P&gt;thanks for your help!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 18:42:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Redact-syslog-using-Splunk/m-p/126344#M25999</guid>
      <dc:creator>zerolife</dc:creator>
      <dc:date>2014-04-11T18:42:52Z</dc:date>
    </item>
  </channel>
</rss>

