Getting Data In

How to unmask fields on adhoc basis?

Chiranjeev88
Explorer

Hi All ,

 

We have a sensitive field that we mask regularly ,but a use case has come where we have to store the particular filed as it is (without masking) based on a  field value .does anyone have faced any case like that before ?

current scenario 

customer_data ==xxxx  specific_filed=abc

customer_data ==xxxx  specific_filed=def

customer_data ==xxxx  specific_filed=ghi

expected output 

based on an adhoc request we have to unmask now the incoming data for field abc

customer_data ==12345 specific_filed=abc

customer_data ==xxxx  specific_filed=def

customer_data ==xxxx  specific_filed=ghi

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you're masking the data using SEDCMD or a transform then there's no "unmasking".  The original data has been replaced and cannot be recovered.

A workaround would be to clone the data to a separate index with limited read access.  Then you'd have to pull the unmasked data from the new index in addition to the masked data from the current index.

Perhaps you can use Ingest Actions to only mask non-abc data.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...