The Getting Data In manual has a topic about how to mask data when indexing. At search time, you could use a regex in your search, or the scrub command. There is also an Encrypt/Decrypt app you might want to look at.
I see you have posted several variations on this question in the past day or two. You should try to consolidate your postings to a single request that includes all the information. That will give the community the best chance of answering you.
I didn't get the answer I want to know. SPlunk should has a way to verify the masking either in indexing or search time. BUt it didn't ..
I have tried a different ways by following the instruction in the link of your posting and other posting, I could not see how SSN was masked
I still saw SSN when doing the search....