Getting Data In

Mask/Encrypt Specific field from universal forwarder agent side

Amirahussein
Path Finder

Hi everybody,

I need your assistance if you have encountered this problem or not since I want to mask a particular field before it is processed by SPLUNK indexers.
I need to mask a particular field because the data will be transferred via a universal forwarder (an externally installed agent).

Regards, Amira

 

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Amirahussein,

you can find the solution to your request in my previous answer https://community.splunk.com/t5/Getting-Data-In/Could-someone-help-me-with-Data-Masking/m-p/613560#M... 

and you can find the Splunk documentation at https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata 

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...