<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Anonymize data from JSON File in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502195#M85569</link>
    <description>&lt;P&gt;I have a json event with an id which I want to anonymize. However, I have to be able to perform stats/count/grouping and other analytics on this id later. In short, I want to hide this id for the users but should be able to be used internally by Splunk. Is this possible?&lt;/P&gt;
&lt;P&gt;My event looks something like this:&lt;/P&gt;
&lt;P&gt;{"duration":0.33,"a":"login","i":"50050","d":"2055502349","c":"LIVE","@timestamp":"2020-05-22T01:59:59.601Z"}&lt;/P&gt;
&lt;P&gt;I want to anonymize "d" id.&lt;/P&gt;</description>
    <pubDate>Sun, 07 Jun 2020 01:29:46 GMT</pubDate>
    <dc:creator>AnujaJ</dc:creator>
    <dc:date>2020-06-07T01:29:46Z</dc:date>
    <item>
      <title>Anonymize data from JSON File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502195#M85569</link>
      <description>&lt;P&gt;I have a json event with an id which I want to anonymize. However, I have to be able to perform stats/count/grouping and other analytics on this id later. In short, I want to hide this id for the users but should be able to be used internally by Splunk. Is this possible?&lt;/P&gt;
&lt;P&gt;My event looks something like this:&lt;/P&gt;
&lt;P&gt;{"duration":0.33,"a":"login","i":"50050","d":"2055502349","c":"LIVE","@timestamp":"2020-05-22T01:59:59.601Z"}&lt;/P&gt;
&lt;P&gt;I want to anonymize "d" id.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 01:29:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502195#M85569</guid>
      <dc:creator>AnujaJ</dc:creator>
      <dc:date>2020-06-07T01:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymize data from JSON File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502196#M85570</link>
      <description>&lt;P&gt;Hello @AnujaJ&lt;/P&gt;

&lt;P&gt;Though I haven't tried this yet, I think this can be achieved by forwarding the anonymized event at index-time to the intended customer index and forward a separate non-anonymized event on an admin-only index. &lt;/P&gt;

&lt;P&gt;Caveat for this is it would double your license usage.&lt;/P&gt;

&lt;P&gt;Please see link below if my answer is what you're aiming for:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/690291/one-source-to-two-indexes.html"&gt;https://answers.splunk.com/answers/690291/one-source-to-two-indexes.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;EDIT:&lt;/P&gt;

&lt;P&gt;You can actually achieve the "one data source (anonymized and non-anonymized) to two indexes solution" without hitting a double license usage:&lt;BR /&gt;
(check woodcock's answer on the link below)&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/567223/how-to-send-same-data-source-to-two-or-multiple-in-1.html"&gt;https://answers.splunk.com/answers/567223/how-to-send-same-data-source-to-two-or-multiple-in-1.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 19:30:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502196#M85570</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2020-05-22T19:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymize data from JSON File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502197#M85571</link>
      <description>&lt;P&gt;UPDATED:&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[anony_json]
INDEXED_EXTRACTIONS = json
KV_MODE = none
TRANSFORMS-anony = anony, anony_raw
TRUNCATE = 0
TIME_PREFIX = timestamp\":\"
SHOULD_LINEMERGE = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[anony]
INGEST_EVAL = d:=md5(d)
WRITE_META = true

[anony_raw]
REGEX = (?m)(.*\"d\":\s*\"\d{4})\d+\"(.*)
FORMAT = $1XXXXXX"$2
DEST_KEY =_raw
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/IngestEval"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/IngestEval&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In my splunk(ver 8), this setting works.&lt;BR /&gt;
I have a few mistakes. I fix them.&lt;/P&gt;

&lt;P&gt;How about this?&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 22:41:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502197#M85571</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-22T22:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymize data from JSON File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502198#M85572</link>
      <description>&lt;P&gt;Thank you for your answer.&lt;/P&gt;

&lt;P&gt;d is single valued. &lt;/P&gt;

&lt;P&gt;However, I cannot use this solution as I would not be able to perform  commands like "|stats count by d" since the indexed value of d will be changed.  I want d to be anonymized for all the users but splunk should be able to internally use it. &lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 07:21:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502198#M85572</guid>
      <dc:creator>AnujaJ</dc:creator>
      <dc:date>2020-05-25T07:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymize data from JSON File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502199#M85573</link>
      <description>&lt;P&gt;Since the actual data is only available to the admin, does it mean that only admin will create the dashboards while other users use customer index? &lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 07:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502199#M85573</guid>
      <dc:creator>AnujaJ</dc:creator>
      <dc:date>2020-05-25T07:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymize data from JSON File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502200#M85574</link>
      <description>&lt;PRE&gt;&lt;CODE&gt; [anony]
 INGEST_EVAL = d=md5(d)
 WRITE_META = true
 [anony_raw]
 REGEX = (\"d\":\s*\")(\d{4})\d+\"
 FORMAT = $1$2XXXXXX"
 DEST_KEY = _raw
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;use &lt;CODE&gt;hash&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 08:14:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502200#M85574</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-25T08:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymize data from JSON File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502201#M85575</link>
      <description>&lt;P&gt;I exactly want this. I changed anony_raw so as to include data before and after. However, the hash is not applied. The script only adds XXX to d instead of calculating hash. &lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;INDEXED_EXTRACTION = json 
KV_MODE = none 
TRANSFORMS-anony = anony, anony_raw
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[anony] 
INGEST_EVAL = d=md5(d)
WRITE_META = true

[anony_raw] 
REGEX = (?m)^(.*)(\"d\":\s*\")(\d{4})\d+\"(.*)
FORMAT = $1$2$3XXXXXX"$4 
DEST_KEY =_raw
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 25 May 2020 13:03:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502201#M85575</guid>
      <dc:creator>AnujaJ</dc:creator>
      <dc:date>2020-05-25T13:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymize data from JSON File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502202#M85576</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/614339/transform-field-in-sha256-before-indexation.html"&gt;https://answers.splunk.com/answers/614339/transform-field-in-sha256-before-indexation.html&lt;/A&gt; suggests this cannot be done. &lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 13:11:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502202#M85576</guid>
      <dc:creator>AnujaJ</dc:creator>
      <dc:date>2020-05-25T13:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymize data from JSON File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502203#M85577</link>
      <description>&lt;P&gt;&lt;CODE&gt;INGEST_EVAL = d=substr(d,5,10).substr(d,1,6).(d%2).(d%3)&lt;/CODE&gt;&lt;BR /&gt;
How's this?&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 20:23:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502203#M85577</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-25T20:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymize data from JSON File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502204#M85578</link>
      <description>&lt;P&gt;This does not work. anony_raw overrides anony so the end result is d: 2055XXXXXX. I want to use md5 so that I can still co-relate data-. &lt;/P&gt;

&lt;P&gt;For props.conf even if I change order of the two properties the end result stays the same. Removing anony_raw makes no changes to the original information. &lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 06:47:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502204#M85578</guid>
      <dc:creator>AnujaJ</dc:creator>
      <dc:date>2020-05-26T06:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymize data from JSON File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502205#M85579</link>
      <description>&lt;P&gt;My answer is updated. please confirm.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 09:27:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/502205#M85579</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-26T09:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymize variables data from JSON File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/504550#M85997</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have the same issue BUT little more complex.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is an example of a json event return in splunk :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://login.splunk.digital.engie.com/en-US/app/splunk_app_aws/search?q=search%20index%3D%22aws_other_*%22%20sourcetype%3D%22aws%3Adescription%22%20source%3D%22*%3Alambda_functions%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-60m%40m&amp;amp;latest=now&amp;amp;sid=1592289970.619684#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;CodeSha256&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;2+1ndsvhz23R2VD42&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;CodeSize&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t number"&gt;1909&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Description&lt;/SPAN&gt;:&amp;nbsp;None&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Environment&lt;/SPAN&gt;:&amp;nbsp;{&amp;nbsp;&lt;A href="https://login.splunk.digital.engie.com/en-US/app/splunk_app_aws/search?q=search%20index%3D%22aws_other_*%22%20sourcetype%3D%22aws%3Adescription%22%20source%3D%22*%3Alambda_functions%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-60m%40m&amp;amp;latest=now&amp;amp;sid=1592289970.619684#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-2"&gt;&lt;SPAN class="key-name"&gt;Variables&lt;/SPAN&gt;:&amp;nbsp;{&amp;nbsp;&lt;A href="https://login.splunk.digital.engie.com/en-US/app/splunk_app_aws/search?q=search%20index%3D%22aws_other_*%22%20sourcetype%3D%22aws%3Adescription%22%20source%3D%22*%3Alambda_functions%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-60m%40m&amp;amp;latest=now&amp;amp;sid=1592289970.619684#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;FONT color="#339966"&gt;&lt;SPAN class="key-name"&gt;CLUSTER_NAME&lt;/SPAN&gt;:&lt;/FONT&gt;&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t string"&gt;Cluster&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;FONT color="#339966"&gt;&lt;SPAN class="key-name"&gt;ENVIRONMENT&lt;/SPAN&gt;&lt;/FONT&gt;:&amp;nbsp;&lt;FONT color="#FF0000"&gt;dev&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;FONT color="#339966"&gt;&lt;SPAN class="key-name"&gt;USER_NAME&lt;/SPAN&gt;&lt;/FONT&gt;:&amp;nbsp;&lt;FONT color="#FF0000"&gt;tata&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;FONT color="#339966"&gt;&lt;SPAN class="key-name"&gt;PASSWD&lt;/SPAN&gt;&lt;/FONT&gt;:&amp;nbsp;&lt;FONT color="#FF0000"&gt;toto!&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;LastModified&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;2019-12-05T10:58:05.308+0000&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;MemorySize&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t number"&gt;128&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;RevisionId&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;f0d723sdf6-c000edfzf&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Runtime&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;python3.6&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Timeout&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t number"&gt;180&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;TracingConfig&lt;/SPAN&gt;:&amp;nbsp;{&amp;nbsp;&lt;A href="https://login.splunk.digital.engie.com/en-US/app/splunk_app_aws/search?q=search%20index%3D%22aws_other_*%22%20sourcetype%3D%22aws%3Adescription%22%20source%3D%22*%3Alambda_functions%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-60m%40m&amp;amp;latest=now&amp;amp;sid=1592289970.619684#" target="_blank" rel="noopener"&gt;[+]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Version&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;$LATEST&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;region&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;eu-east-1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The problem is that &lt;STRONG&gt;sensitive data&lt;/STRONG&gt; &lt;STRONG&gt;appear&lt;/STRONG&gt; in clear specifically&amp;nbsp; in &lt;STRONG&gt;Environment&amp;gt;Variables&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;In this section, we have &lt;STRONG&gt;variables&lt;/STRONG&gt; : we can not create a regex with specific key name because it always changes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How can I mask all values in the&amp;nbsp;Environment&amp;gt;Variables WITHOUT masking the key ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Example of result I want :&lt;/P&gt;&lt;P&gt;{&amp;nbsp;&lt;A href="https://login.splunk.digital.engie.com/en-US/app/splunk_app_aws/search?q=search%20index%3D%22aws_other_*%22%20sourcetype%3D%22aws%3Adescription%22%20source%3D%22*%3Alambda_functions%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-60m%40m&amp;amp;latest=now&amp;amp;sid=1592289970.619684#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;CodeSha256&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;2+1ndsvhz23R2VD42&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;CodeSize&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t number"&gt;1909&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Description&lt;/SPAN&gt;:&amp;nbsp;None&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Environment&lt;/SPAN&gt;:&amp;nbsp;{&amp;nbsp;&lt;A href="https://login.splunk.digital.engie.com/en-US/app/splunk_app_aws/search?q=search%20index%3D%22aws_other_*%22%20sourcetype%3D%22aws%3Adescription%22%20source%3D%22*%3Alambda_functions%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-60m%40m&amp;amp;latest=now&amp;amp;sid=1592289970.619684#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-2"&gt;&lt;SPAN class="key-name"&gt;Variables&lt;/SPAN&gt;:&amp;nbsp;{&amp;nbsp;&lt;A href="https://login.splunk.digital.engie.com/en-US/app/splunk_app_aws/search?q=search%20index%3D%22aws_other_*%22%20sourcetype%3D%22aws%3Adescription%22%20source%3D%22*%3Alambda_functions%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-60m%40m&amp;amp;latest=now&amp;amp;sid=1592289970.619684#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;FONT color="#339966"&gt;&lt;SPAN class="key-name"&gt;CLUSTER_NAME&lt;/SPAN&gt;:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;FONT color="#339966"&gt;&lt;SPAN class="key-name"&gt;ENVIRONMENT&lt;/SPAN&gt;&lt;/FONT&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;FONT color="#339966"&gt;&lt;SPAN class="key-name"&gt;USER_NAME&lt;/SPAN&gt;&lt;/FONT&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;FONT color="#339966"&gt;&lt;SPAN class="key-name"&gt;PASSWD&lt;/SPAN&gt;&lt;/FONT&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;LastModified&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;2019-12-05T10:58:05.308+0000&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;MemorySize&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t number"&gt;128&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;RevisionId&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;f0d723sdf6-c000edfzf&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Runtime&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;python3.6&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Timeout&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t number"&gt;180&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;TracingConfig&lt;/SPAN&gt;:&amp;nbsp;{&amp;nbsp;&lt;A href="https://login.splunk.digital.engie.com/en-US/app/splunk_app_aws/search?q=search%20index%3D%22aws_other_*%22%20sourcetype%3D%22aws%3Adescription%22%20source%3D%22*%3Alambda_functions%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-60m%40m&amp;amp;latest=now&amp;amp;sid=1592289970.619684#" target="_blank" rel="noopener"&gt;[+]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;Version&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;$LATEST&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-1"&gt;&lt;SPAN class="key-name"&gt;region&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;eu-east-1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;}&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 06:59:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anonymize-data-from-JSON-File/m-p/504550#M85997</guid>
      <dc:creator>mah</dc:creator>
      <dc:date>2020-06-16T06:59:25Z</dc:date>
    </item>
  </channel>
</rss>

