Getting Data In

How to unmask fields on adhoc basis?


Hi All ,


We have a sensitive field that we mask regularly ,but a use case has come where we have to store the particular filed as it is (without masking) based on a  field value .does anyone have faced any case like that before ?

current scenario 

customer_data ==xxxx  specific_filed=abc

customer_data ==xxxx  specific_filed=def

customer_data ==xxxx  specific_filed=ghi

expected output 

based on an adhoc request we have to unmask now the incoming data for field abc

customer_data ==12345 specific_filed=abc

customer_data ==xxxx  specific_filed=def

customer_data ==xxxx  specific_filed=ghi


0 Karma


If you're masking the data using SEDCMD or a transform then there's no "unmasking".  The original data has been replaced and cannot be recovered.

A workaround would be to clone the data to a separate index with limited read access.  Then you'd have to pull the unmasked data from the new index in addition to the masked data from the current index.

Perhaps you can use Ingest Actions to only mask non-abc data.

If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...