Hi,
We are ingesting some logs into splunk in JSON format, the logs are ingested via TA.
The value field in the below contains bank details which has to be masked.
PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.SensitiveInformationDetections.DetectedValues{}.Value
Hi @VijaySrrie ,
I have given a sample config below. You can try like that.
props.conf
[mentionsourcetype]
TRANSFORMS-acctmasking = mask-acctcode
Transforms.conf
[mask-acctcode]
REGEX = (.*DetectedValues{}.Value=\d+).*
DEST_KEY = _raw
FORMAT = $1-XXXX