<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I mask data - both at index time and search time? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26762#M4450</link>
    <description>&lt;P&gt;I downvoted this post because because it only works if you write every search for the users&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2017 05:56:39 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2017-07-27T05:56:39Z</dc:date>
    <item>
      <title>How can I mask data - both at index time and search time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26754#M4442</link>
      <description>&lt;P&gt;I found out that in one of my web logs that Splunk's been eating, there's data that I need to mask out.  So, I've got two problems to solve: &lt;/P&gt;

&lt;P&gt;(a) Removing the sensitive data (though not the WHOLE event) from already-indexed data, and&lt;/P&gt;

&lt;P&gt;(b) Making it so newly-indexed data has this same data masked.  &lt;/P&gt;

&lt;P&gt;What's my best way to approach this?  It's data like this that I'm trying to mask:&lt;/P&gt;

&lt;P&gt;173.103.16.2 - - [10/Jun/2011:16:09:27 -0500] "GET /admin/load-scripts.jsp?c=1&amp;amp;failedPassword=FAILEDPASSWORDIWANTTOMASK&amp;amp;otheroptions=3&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2011 21:14:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26754#M4442</guid>
      <dc:creator>tadreeves</dc:creator>
      <dc:date>2011-06-10T21:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: How can I mask data - both at index time and search time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26755#M4443</link>
      <description>&lt;P&gt;You can &lt;A href="http://www.splunk.com/base/Documentation/4.2.1/Data/Anonymizedatausingconfigurationfiles"&gt;mask sensitive data&lt;/A&gt; at index time. (Ask more questions if that's not sufficient information!)&lt;/P&gt;

&lt;P&gt;However, once the data has been indexed, there is &lt;STRONG&gt;no way&lt;/STRONG&gt; to change it. Not possible.&lt;BR /&gt;&lt;BR /&gt;
All you can do it &lt;A href="http://www.splunk.com/base/Documentation/4.2.1/Admin/RemovedatafromSplunk"&gt;delete the data&lt;/A&gt; and re-index it.  You can't mask it at search time.&lt;/P&gt;

&lt;P&gt;I know that isn't the answer that you wanted... sorry!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2011 21:50:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26755#M4443</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2011-06-10T21:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: How can I mask data - both at index time and search time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26756#M4444</link>
      <description>&lt;P&gt;If you’re willing to use a third-party tool (Eclipse GUI) for masking, you can mask it next time (before you re-index it) with this one:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.iri.com/blog/data-protection/secure-then-splunk-a-format-preserving-encryption-and-pseduonymization-example/"&gt;http://www.iri.com/blog/data-protection/secure-then-splunk-a-format-preserving-encryption-and-pseduonymization-example/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2015 14:02:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26756#M4444</guid>
      <dc:creator>MicroAlpha</dc:creator>
      <dc:date>2015-03-20T14:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: How can I mask data - both at index time and search time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26757#M4445</link>
      <description>&lt;P&gt;This is a simple trick to mask data at search time. Get the part of the event to mask with a "rex" command, then modify the "_raw" field with the masked data.&lt;BR /&gt;
From original event, trim the last 5 digit from accountNumber. Original event:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2016-04-06 12:24:06,Event [Event=UpdateBillingProvQuote, timestamp=1337891259, properties={JMSCorrelationID=NA, JMSMessageID=ID:ESP-PD.F4CB3B4B9EF87:AA49A1BD, orderType=FeatureChange, quotePriority=NORMAL, conversationId=ESB~16214F4A71D1DA77:E35B0544:0F2958EEF3F0:B580, credits=NA, JMSReplyTo=pub.esb.genericasync.response, timeToLive=-1, serviceName=UpdateBillingProvisioning, esn=7F758AD4A3B86F, accountNumber=900013479, MethodName=InternalEvent, AdapterName=UpdateBillingProvQuote, meid=NA, orderNumber=19256698, quoteNumber=75909847, ReplyTo=NA, userName=temordia, EventConversationID=NA, mdn=5789374447, accountType=PrePaid, marketCity="ARVADA", marketState=CO, marketZip=80006, billingCycle=27, autoBillPayment=T, phoneCode=HE4G, phoneType=Android, phoneName="HTC Evo 4G", planCode=ULPRE50, planType=PrePaid, planPrice=50.00, planName="Unlimited Prepaid", planDescription="Nationwide Prepaid Unlimited Minutes", networkProviderName=Splunktel}]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;New search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=oidemo sourcetype=business_event | rex "^(?&amp;lt;head&amp;gt;.*accountNumber=\d+)\d{5},(?&amp;lt;tail&amp;gt;.*)$" | eval _raw=head."XXXX".tail
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The new event now looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2016-04-06 12:24:06,Event [Event=UpdateBillingProvQuote, timestamp=1337891259, properties={JMSCorrelationID=NA, JMSMessageID=ID:ESP-PD.F4CB3B4B9EF87:AA49A1BD, orderType=FeatureChange, quotePriority=NORMAL, conversationId=ESB~16214F4A71D1DA77:E35B0544:0F2958EEF3F0:B580, credits=NA, JMSReplyTo=pub.esb.genericasync.response, timeToLive=-1, serviceName=UpdateBillingProvisioning, esn=7F758AD4A3B86F, accountNumber=9000XXXX MethodName=InternalEvent, AdapterName=UpdateBillingProvQuote, meid=NA, orderNumber=19256698, quoteNumber=75909847, ReplyTo=NA, userName=temordia, EventConversationID=NA, mdn=5789374447, accountType=PrePaid, marketCity="ARVADA", marketState=CO, marketZip=80006, billingCycle=27, autoBillPayment=T, phoneCode=HE4G, phoneType=Android, phoneName="HTC Evo 4G", planCode=ULPRE50, planType=PrePaid, planPrice=50.00, planName="Unlimited Prepaid", planDescription="Nationwide Prepaid Unlimited Minutes", networkProviderName=Splunktel}]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 06 Apr 2016 10:30:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26757#M4445</guid>
      <dc:creator>marcoscala</dc:creator>
      <dc:date>2016-04-06T10:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: How can I mask data - both at index time and search time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26758#M4446</link>
      <description>&lt;P&gt;This works perfectly!!&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 19:08:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26758#M4446</guid>
      <dc:creator>rajbir1</dc:creator>
      <dc:date>2017-07-25T19:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: How can I mask data - both at index time and search time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26759#M4447</link>
      <description>&lt;P&gt;I downvoted this post because there is a way to mask sensitive data at search time now as well. please see the last answer below&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 19:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26759#M4447</guid>
      <dc:creator>rajbir1</dc:creator>
      <dc:date>2017-07-25T19:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: How can I mask data - both at index time and search time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26760#M4448</link>
      <description>&lt;P&gt;This solution does not meet my definition of "masking" &lt;/P&gt;

&lt;P&gt;This hides the data for &lt;STRONG&gt;just this search alone.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;So this solution will work only in a dashboard and only if you have also disabled drill-down and disabled "open in search." A user who drills down - or who uses the magnifying class to "open in search" - will be able to circumvent the masking.&lt;/P&gt;

&lt;P&gt;Thus my earlier answer.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 05:53:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26760#M4448</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2017-07-27T05:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: How can I mask data - both at index time and search time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26761#M4449</link>
      <description>&lt;P&gt;I disagree with your down-vote. See my comment below. &lt;/P&gt;

&lt;P&gt;Being able to hide the data in a single search does not mask it. For the "trick" to work,  users cannot be allowed to access the search bar. &lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 05:55:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26761#M4449</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2017-07-27T05:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: How can I mask data - both at index time and search time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26762#M4450</link>
      <description>&lt;P&gt;I downvoted this post because because it only works if you write every search for the users&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 05:56:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26762#M4450</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2017-07-27T05:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: How can I mask data - both at index time and search time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26763#M4451</link>
      <description>&lt;P&gt;Lisa, I do agree with your comments but it happened also to us to have users requiring this visibility to the original raw data limited to only certain roles. So the solution of "masking" at search time with "rex", together with disabling drilldown it was the solution we adopted.&lt;/P&gt;

&lt;P&gt;Do you know of any other search time solution?&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 12:45:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26763#M4451</guid>
      <dc:creator>marcoscala</dc:creator>
      <dc:date>2017-07-27T12:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: How can I mask data - both at index time and search time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26764#M4452</link>
      <description>&lt;P&gt;There is no way to mask the data for only a subset of users at search time - unless you are going to write every search for that subset of users, and restrict those users accessing the search bar in any way.&lt;/P&gt;

&lt;P&gt;One alternative could be to route only the sensitive data to a special index. Most of the data then could go to indexes that are widely visible, and that users can search. The sensitive data then would go in a special index that only some roles could access. For others to access the special index, they could be required to use dashboards, etc. that limit/mask their access. You would still need to be careful with those dashboards, etc. to make use that techniques like drill-down would not compromise the security of the data.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2017 16:44:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26764#M4452</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2017-07-31T16:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: How can I mask data - both at index time and search time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26765#M4453</link>
      <description>&lt;P&gt;You are right, there is no way to mask the data at search time. This solution is only for the purposes of hiding the data for specific dashboard panel/report. &lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2017 18:34:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-mask-data-both-at-index-time-and-search-time/m-p/26765#M4453</guid>
      <dc:creator>rajbir1</dc:creator>
      <dc:date>2017-07-31T18:34:16Z</dc:date>
    </item>
  </channel>
</rss>

