Getting Data In

Masking email

toporagno
Explorer

i need to masking email on my data, i'm tring using transforms.com but

[emailaddr-anonymizer]
REGEX = ([A-z0-9._%+-]+@[A-z0-9.-]+\.[A-z]{2,63})
FORMAT = ********@*********
DEST_KEY = _raw

 if I do this the entire log is masked, however I want only the email to be masked,

please can someone help me

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The easier way to mask data is with SEDCMD in props.conf.

SEDCMD-emailaddr-anonymizer = s/([A-z0-9\._%+-]+@[A-z0-9\.-]+\.[A-z]{2,63})/********@*********/g

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The easier way to mask data is with SEDCMD in props.conf.

SEDCMD-emailaddr-anonymizer = s/([A-z0-9\._%+-]+@[A-z0-9\.-]+\.[A-z]{2,63})/********@*********/g

 

---
If this reply helps you, Karma would be appreciated.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...