Getting Data In

Anonymize data by editing your own custom script

sarahh
Engager

May I know if there is any way to anonymise/mask the data in our search results by using our own custom commands, by editing our own custom script? For example, in the search results, I want to anonymise a certain interesting field by coding in my own custom script. Is it possible? Are there any guide to it? Thanks.

Tags (1)
0 Karma

kallu
Communicator

If you want to extend Splunk with your legacy scripts, maybe this example helps you to get started.
If you just want to anonymize your logs before sending them to some 3rd party, maybe scrub -cmd could do it for you without custom scripts?

None of these actually can hide your data that has been indexed by Splunk. These only manipulate search results. You can still dig out the original data using another search. If it is something really sensitive you should do the masking & hashing at indexing time. Not sure how/if custom code could be used in that case.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...