Getting Data In

Delete PII from Splunk

ryan_gates
Explorer

We're using Splunk for logging from multiple applications. Some of these applications deal with PII data.

If one of those applications puts the PII data in Splunk, how can it be removed or deleted?

I need to remove the data from the machine and Splunk.

0 Karma

hsesterhenn_spl
Splunk Employee
Splunk Employee

Hi,

there are some options... but remember Splunk is more like an event recorder.

Since most of the fields are extracted at search time, we can't identify PII data at ingestion time.

Easiest thing is to scrub the data at ingestion time... props/transforms.conf -> anonymize the data

The "delete" command does not really delete, it marks "as deleted".

You can set the retention time in the index accordingly... data will be removed completely.

If you need to remove a specific event, you might dump the index via a search, remove the index and then re-index it... not nice but an option.

Again, Splunk is not an RDBMS where you just delete a row.

HTH,

Holger

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...