<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Partial obfuscation in Splunk Cloud in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Partial-obfuscation-in-Splunk-Cloud/m-p/555999#M92061</link>
    <description>&lt;P&gt;Hello experts,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm trying to obfuscate the UserName and ComputerName from my events before indexation, while keeping the possibility of using the data to group from a common source.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Configuration: data are pushed by a UniversalForwarder (no transform options) to a SplunkCloud instance (limited setup).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;I have this:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;time1|UserName=&lt;STRONG&gt;&lt;FONT color="#808080"&gt;user1&lt;/FONT&gt;&lt;/STRONG&gt;|ComputerName=&lt;STRONG&gt;&lt;FONT color="#808080"&gt;FR1234&lt;/FONT&gt;&lt;/STRONG&gt;|EventStart&lt;BR /&gt;time2|UserName=&lt;STRONG&gt;&lt;FONT color="#808080"&gt;user1&lt;/FONT&gt;&lt;/STRONG&gt;|ComputerName=&lt;STRONG&gt;&lt;FONT color="#808080"&gt;FR1234&lt;/FONT&gt;&lt;/STRONG&gt;|EventEnd&lt;BR /&gt;time3|UserName=&lt;STRONG&gt;&lt;FONT color="#333399"&gt;user2&lt;/FONT&gt;&lt;/STRONG&gt;|ComputerName=&lt;STRONG&gt;&lt;FONT color="#333399"&gt;US4321&lt;/FONT&gt;&lt;/STRONG&gt;|EventStart&lt;BR /&gt;time4|UserName=&lt;STRONG&gt;&lt;FONT color="#333399"&gt;user2&lt;/FONT&gt;&lt;/STRONG&gt;|ComputerName=&lt;STRONG&gt;&lt;FONT color="#333399"&gt;US4321&lt;/FONT&gt;&lt;/STRONG&gt;|EventEnd&lt;BR /&gt;time5|UserName=&lt;STRONG&gt;user1&lt;/STRONG&gt;|ComputerName=&lt;STRONG&gt;&lt;FONT color="#FF9900"&gt;US4321&lt;/FONT&gt;&lt;/STRONG&gt;|EventStart&lt;BR /&gt;time6|UserName=&lt;STRONG&gt;user1&lt;/STRONG&gt;|ComputerName=&lt;STRONG&gt;&lt;FONT color="#FF9900"&gt;US4321&lt;/FONT&gt;&lt;/STRONG&gt;|EventEnd&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And want something like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;time1|UserName=#####|ComputerName=FR#|GeneratedSessionID=&lt;STRONG&gt;&lt;FONT color="#808080"&gt;eifiweuh&lt;/FONT&gt;&lt;/STRONG&gt;|EventStart&lt;BR /&gt;time2|UserName=#####|ComputerName=FR#|GeneratedSessionID=&lt;STRONG&gt;&lt;FONT color="#808080"&gt;eifiweuh&lt;/FONT&gt;&lt;/STRONG&gt;|EventEnd&lt;BR /&gt;time3|UserName=#####|ComputerName=US#|GeneratedSessionID=&lt;STRONG&gt;&lt;FONT color="#333399"&gt;fwefwe&lt;/FONT&gt;&lt;/STRONG&gt;|EventStart&lt;BR /&gt;time4|UserName=#####|ComputerName=US#|GeneratedSessionID=&lt;STRONG&gt;&lt;FONT color="#333399"&gt;fwefwe&lt;/FONT&gt;&lt;/STRONG&gt;|EventEnd&lt;BR /&gt;time5|UserName=#####|ComputerName=US#|GeneratedSessionID=&lt;STRONG&gt;&lt;FONT color="#FF9900"&gt;hkukuyy&lt;/FONT&gt;&lt;/STRONG&gt;|EventStart&lt;BR /&gt;time6|UserName=#####|ComputerName=US#|GeneratedSessionID=&lt;STRONG&gt;&lt;FONT color="#FF9900"&gt;hkukuyy&lt;/FONT&gt;&lt;/STRONG&gt;|EventEnd&lt;/P&gt;&lt;P&gt;Where&amp;nbsp;&lt;SPAN&gt;GeneratedSessionID=function(user1,FR1234,encryptKey) or something similar. Meaning that the same couple computer+user will always create the same GeneratedSessionID&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I'm looking at adding a SECCMD setting on the &lt;EM&gt;Advanced&lt;/EM&gt; tab of my &lt;EM&gt;SourceType&lt;/EM&gt;. I see how to anonymize the UserName and ComputerName, but not how to add a new field based on the others.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Flobzh_0-1623853581312.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14664i01F265694D0F706D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Flobzh_0-1623853581312.png" alt="Flobzh_0-1623853581312.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Flobzh_0-1623853581312.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any advise in that direction would be welcome, or any solution that will match with the restriction of my configuration.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Florent&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jun 2021 14:33:32 GMT</pubDate>
    <dc:creator>Flobzh</dc:creator>
    <dc:date>2021-06-16T14:33:32Z</dc:date>
    <item>
      <title>Partial obfuscation in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Partial-obfuscation-in-Splunk-Cloud/m-p/555999#M92061</link>
      <description>&lt;P&gt;Hello experts,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm trying to obfuscate the UserName and ComputerName from my events before indexation, while keeping the possibility of using the data to group from a common source.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Configuration: data are pushed by a UniversalForwarder (no transform options) to a SplunkCloud instance (limited setup).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;I have this:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;time1|UserName=&lt;STRONG&gt;&lt;FONT color="#808080"&gt;user1&lt;/FONT&gt;&lt;/STRONG&gt;|ComputerName=&lt;STRONG&gt;&lt;FONT color="#808080"&gt;FR1234&lt;/FONT&gt;&lt;/STRONG&gt;|EventStart&lt;BR /&gt;time2|UserName=&lt;STRONG&gt;&lt;FONT color="#808080"&gt;user1&lt;/FONT&gt;&lt;/STRONG&gt;|ComputerName=&lt;STRONG&gt;&lt;FONT color="#808080"&gt;FR1234&lt;/FONT&gt;&lt;/STRONG&gt;|EventEnd&lt;BR /&gt;time3|UserName=&lt;STRONG&gt;&lt;FONT color="#333399"&gt;user2&lt;/FONT&gt;&lt;/STRONG&gt;|ComputerName=&lt;STRONG&gt;&lt;FONT color="#333399"&gt;US4321&lt;/FONT&gt;&lt;/STRONG&gt;|EventStart&lt;BR /&gt;time4|UserName=&lt;STRONG&gt;&lt;FONT color="#333399"&gt;user2&lt;/FONT&gt;&lt;/STRONG&gt;|ComputerName=&lt;STRONG&gt;&lt;FONT color="#333399"&gt;US4321&lt;/FONT&gt;&lt;/STRONG&gt;|EventEnd&lt;BR /&gt;time5|UserName=&lt;STRONG&gt;user1&lt;/STRONG&gt;|ComputerName=&lt;STRONG&gt;&lt;FONT color="#FF9900"&gt;US4321&lt;/FONT&gt;&lt;/STRONG&gt;|EventStart&lt;BR /&gt;time6|UserName=&lt;STRONG&gt;user1&lt;/STRONG&gt;|ComputerName=&lt;STRONG&gt;&lt;FONT color="#FF9900"&gt;US4321&lt;/FONT&gt;&lt;/STRONG&gt;|EventEnd&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And want something like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;time1|UserName=#####|ComputerName=FR#|GeneratedSessionID=&lt;STRONG&gt;&lt;FONT color="#808080"&gt;eifiweuh&lt;/FONT&gt;&lt;/STRONG&gt;|EventStart&lt;BR /&gt;time2|UserName=#####|ComputerName=FR#|GeneratedSessionID=&lt;STRONG&gt;&lt;FONT color="#808080"&gt;eifiweuh&lt;/FONT&gt;&lt;/STRONG&gt;|EventEnd&lt;BR /&gt;time3|UserName=#####|ComputerName=US#|GeneratedSessionID=&lt;STRONG&gt;&lt;FONT color="#333399"&gt;fwefwe&lt;/FONT&gt;&lt;/STRONG&gt;|EventStart&lt;BR /&gt;time4|UserName=#####|ComputerName=US#|GeneratedSessionID=&lt;STRONG&gt;&lt;FONT color="#333399"&gt;fwefwe&lt;/FONT&gt;&lt;/STRONG&gt;|EventEnd&lt;BR /&gt;time5|UserName=#####|ComputerName=US#|GeneratedSessionID=&lt;STRONG&gt;&lt;FONT color="#FF9900"&gt;hkukuyy&lt;/FONT&gt;&lt;/STRONG&gt;|EventStart&lt;BR /&gt;time6|UserName=#####|ComputerName=US#|GeneratedSessionID=&lt;STRONG&gt;&lt;FONT color="#FF9900"&gt;hkukuyy&lt;/FONT&gt;&lt;/STRONG&gt;|EventEnd&lt;/P&gt;&lt;P&gt;Where&amp;nbsp;&lt;SPAN&gt;GeneratedSessionID=function(user1,FR1234,encryptKey) or something similar. Meaning that the same couple computer+user will always create the same GeneratedSessionID&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I'm looking at adding a SECCMD setting on the &lt;EM&gt;Advanced&lt;/EM&gt; tab of my &lt;EM&gt;SourceType&lt;/EM&gt;. I see how to anonymize the UserName and ComputerName, but not how to add a new field based on the others.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Flobzh_0-1623853581312.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14664i01F265694D0F706D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Flobzh_0-1623853581312.png" alt="Flobzh_0-1623853581312.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Flobzh_0-1623853581312.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any advise in that direction would be welcome, or any solution that will match with the restriction of my configuration.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Florent&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 14:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Partial-obfuscation-in-Splunk-Cloud/m-p/555999#M92061</guid>
      <dc:creator>Flobzh</dc:creator>
      <dc:date>2021-06-16T14:33:32Z</dc:date>
    </item>
  </channel>
</rss>

