Getting Data In

How to unmask fields on adhoc basis?

Chiranjeev88
Explorer

Hi All ,

 

We have a sensitive field that we mask regularly ,but a use case has come where we have to store the particular filed as it is (without masking) based on a  field value .does anyone have faced any case like that before ?

current scenario 

customer_data ==xxxx  specific_filed=abc

customer_data ==xxxx  specific_filed=def

customer_data ==xxxx  specific_filed=ghi

expected output 

based on an adhoc request we have to unmask now the incoming data for field abc

customer_data ==12345 specific_filed=abc

customer_data ==xxxx  specific_filed=def

customer_data ==xxxx  specific_filed=ghi

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you're masking the data using SEDCMD or a transform then there's no "unmasking".  The original data has been replaced and cannot be recovered.

A workaround would be to clone the data to a separate index with limited read access.  Then you'd have to pull the unmasked data from the new index in addition to the masked data from the current index.

Perhaps you can use Ingest Actions to only mask non-abc data.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...