<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can I replace a field at parsing stage with a hash (using sha2 for example)? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303471#M57293</link>
    <description>&lt;P&gt;Hi answers! I would like to replace some information I get in Splunk.&lt;BR /&gt;
For example, I get some user names (user=karlo) for example. I would like to replace this with a hash value.&lt;/P&gt;

&lt;P&gt;I have learned about SEDCMD and transforms. In there I know I can replace some characters with XXXX-es. This will not do in this case.&lt;/P&gt;

&lt;P&gt;Replacing the values with a hash, before getting indexed/written to disk, and using my own salt, would be very nice. Can someone provide me with a hint if this is possible, and if so: how to do it?&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2018 03:47:15 GMT</pubDate>
    <dc:creator>_karlo</dc:creator>
    <dc:date>2018-01-12T03:47:15Z</dc:date>
    <item>
      <title>Can I replace a field at parsing stage with a hash (using sha2 for example)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303471#M57293</link>
      <description>&lt;P&gt;Hi answers! I would like to replace some information I get in Splunk.&lt;BR /&gt;
For example, I get some user names (user=karlo) for example. I would like to replace this with a hash value.&lt;/P&gt;

&lt;P&gt;I have learned about SEDCMD and transforms. In there I know I can replace some characters with XXXX-es. This will not do in this case.&lt;/P&gt;

&lt;P&gt;Replacing the values with a hash, before getting indexed/written to disk, and using my own salt, would be very nice. Can someone provide me with a hint if this is possible, and if so: how to do it?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 03:47:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303471#M57293</guid>
      <dc:creator>_karlo</dc:creator>
      <dc:date>2018-01-12T03:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can I replace a field at parsing stage with a hash (using sha2 for example)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303472#M57294</link>
      <description>&lt;P&gt;There is no way to run code at index time once the event is presented to Splunk. So, &lt;CODE&gt;monitor&lt;/CODE&gt; inputs, etc have no way to do this.&lt;/P&gt;

&lt;P&gt;But, if the necessity to accomplish this exists, you can look into scripted or &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/AdvancedDev/ModInputsIntro"&gt;modular inputs&lt;/A&gt; to meet this need.&lt;/P&gt;

&lt;P&gt;Basically you would write code that reads the file and does the replacement, and Splunk would call that code.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 03:55:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303472#M57294</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-01-12T03:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can I replace a field at parsing stage with a hash (using sha2 for example)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303473#M57295</link>
      <description>&lt;P&gt;Thanks for your reply. That is unfortunate. I will wait for a shot time if someone else has some answer, and accept next week if there is no other way. Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 04:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303473#M57295</guid>
      <dc:creator>_karlo</dc:creator>
      <dc:date>2018-01-12T04:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can I replace a field at parsing stage with a hash (using sha2 for example)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303474#M57296</link>
      <description>&lt;P&gt;I, too, hope my answer proves to be wrong. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 04:06:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303474#M57296</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-01-12T04:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Can I replace a field at parsing stage with a hash (using sha2 for example)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303475#M57297</link>
      <description>&lt;P&gt;@_karlo, you can refer to Nimish Doshi's App on Splunkbase &lt;A href="https://splunkbase.splunk.com/app/282/"&gt;Encrypt and Decrypt data within Events&lt;/A&gt;. You can also check out his blog: &lt;A href="https://www.splunk.com/blog/2010/01/25/encrypting-and-decrypting-fields.html"&gt;https://www.splunk.com/blog/2010/01/25/encrypting-and-decrypting-fields.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 04:52:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303475#M57297</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-01-12T04:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can I replace a field at parsing stage with a hash (using sha2 for example)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303476#M57298</link>
      <description>&lt;P&gt;Note that this is now possible in Splunk 7.2 with the new ingest eval capability.&lt;/P&gt;

&lt;P&gt;You can, for instance, apply the eval sha512 function to a field to create a new field:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.0/Data/IngestEval"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.0/Data/IngestEval&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 23:47:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-a-field-at-parsing-stage-with-a-hash-using-sha2/m-p/303476#M57298</guid>
      <dc:creator>stuartidelta01</dc:creator>
      <dc:date>2018-11-28T23:47:26Z</dc:date>
    </item>
  </channel>
</rss>

