Getting Data In

Anonymize data by editing your own custom script

sarahh
Engager

May I know if there is any way to anonymise/mask the data in our search results by using our own custom commands, by editing our own custom script? For example, in the search results, I want to anonymise a certain interesting field by coding in my own custom script. Is it possible? Are there any guide to it? Thanks.

Tags (1)
0 Karma

kallu
Communicator

If you want to extend Splunk with your legacy scripts, maybe this example helps you to get started.
If you just want to anonymize your logs before sending them to some 3rd party, maybe scrub -cmd could do it for you without custom scripts?

None of these actually can hide your data that has been indexed by Splunk. These only manipulate search results. You can still dig out the original data using another search. If it is something really sensitive you should do the masking & hashing at indexing time. Not sure how/if custom code could be used in that case.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...