Getting Data In

masking password with rex command

moin140586
New Member

hi i have a data where there are two fields with password which i need to mask via props.conf and also in the search.

the data looks like this : "this is the test message to demonstrate two fields of password abc.password=QWERTYUI and in the same line we also have another password like xyyz.password=Q%1^WRTy."

rex field=_raw mode=sed "s/abc\.password=\w+/abc.password=XXXXXXXX/g"

i was trying my luck in the search first. i cannot do the masking in single rex sed command for both the passwords . i was able to do sucessfully for first one as its not having special characters.

Regards,

Moin

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @moin140586,

in your regex I see that you didin't escaped "=", anyway, try something like this:

| makeresults 
| eval _raw="this is the test message to demonstrate two fields of password abc.password=QWERTYUI and in the same line we also have another password like xyyz.password=Q%1^WRTy."
| rex mode=sed "s/abc\.password\=\w+.*xyyz\.password\=.*/abc\.password\=********.*xyyz\.password\=********/g"

The regex can be used also in props.conf:

SEDCMD-anonymize = s/abc\.password\=\w+.*xyyz\.password\=.*/abc\.password\=********.*xyyz\.password\=********/g

If you can share a sample of your logs I could be more precise.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...