Splunk Cloud Platform

Anonymizing AWS S3 inputs to Splunk Cloud

sholt_fundrise
New Member

How can I anonymize certain fields from data inputs in Splunk Cloud when ingesting logs from AWS S3 buckets?

Tags (1)
0 Karma

sudosplunk
Motivator

Hi there,

You can make use of regex to look for fields and mask them with props.conf and transforms.conf files. Please provide some info about your architecture and some sample events if you want help with .conf settings.

Please refer to this link for instructions.

0 Karma

sholt_fundrise
New Member

Is that the same steps for Splunk Cloud as it is for Splunk Enterprise?
I'm looking at some CloudFront logs being ingested through an s3 bucket input into a Cloud instance. I found some notes at https://answers.splunk.com/answers/149597/im-struggling-with-how-i-should-be-doing-inputs-and-also-p... that might apply, but I've also found notes saying it's impossible to anonymize this data after indexing. Do I need to be transforming it with a sed script before even having Splunk Cloud in the picture, or is there a configuration i'm missing (field transform?)?

0 Karma

sudosplunk
Motivator

Per documentation, "To anonymize data with Splunk Cloud, you must configure a Splunk Enterprise instance as a heavy forwarder and anonymize the incoming data with that instance before sending it to Splunk Cloud. You can follow the instructions in this topic on the heavy forwarder."

Yes. Once data is indexed, you can't change it. You should mask your data before it touches indexers in cloud.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...