Getting Data In

Anonymize Data in Splunk Search

jmaguire1992
Explorer

Hey,
I am running a local instance of splunk for testing purposes. The aim is toAnonymize certain parts of the data that can be searched.
In my files there were no props.conf or transforms.conf so I created these two files in this folder

'C:\Program Files\Splunk\etc\system\local'

The data I am looking to anonymize is simple
testfield: 123
- Either by removing it completely or removing the unit.

If anyone could help with what exactly should go in the transforms.conf and the props.conf files that would be greatly appreciated.

Thank you,

0 Karma
1 Solution

DMohn
Motivator

Assuming you want to anonymize the '123' in your test data, you could use the following configuration:

props.conf

 [your_sourcetype]
 TRANSFORMS-anonymize = testdata_anonymizer

transforms.conf

 [testdata_anonymizer]
 REGEX = (?m)^testfield:\s+(.*)$
 FORMAT = testfield:\sxxxx
 DEST_KEY = _raw

This will strip all off your event after the 'testfield: ' string, and replace it with 'xxxx'
If you want to keep some of the data, you have to modify the regex accordingly.

View solution in original post

DMohn
Motivator

Assuming you want to anonymize the '123' in your test data, you could use the following configuration:

props.conf

 [your_sourcetype]
 TRANSFORMS-anonymize = testdata_anonymizer

transforms.conf

 [testdata_anonymizer]
 REGEX = (?m)^testfield:\s+(.*)$
 FORMAT = testfield:\sxxxx
 DEST_KEY = _raw

This will strip all off your event after the 'testfield: ' string, and replace it with 'xxxx'
If you want to keep some of the data, you have to modify the regex accordingly.

jmaguire1992
Explorer

Thank you very much! It worked! It removed all of the other data and just left

testfield:\sxxxx

So I will try figure out some way of modifying the regex to just Anoymize the testfield, but thank you so much for your helpful comment 🙂

0 Karma

jaiminsol
New Member

Hi Sir,
Are you able to modify the regex to replace only 123 data . not all other fields in the even. IF yes Could you please provide the regex. Thanks in advance for your help .

0 Karma

DMohn
Motivator

You can modify the regex to capture only the next three digits after 'testfield:' this way:
REGEX = (?m)testfield:\s+(\d{3})
FORMAT = testfield:\sxxxx

This will capture any string 'testfield:' followed by a space and three digits.

0 Karma

somesoni2
Revered Legend
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...