Splunk Search
Highlighted

Mask SSN on forwarder/Indexer?

New Member

Tried this on both the Forwarder & indexer without success, what am i missing ?

Log output SignUpState='3.30' SSN='555555555'
desired output SSN='xxxxxxxxx'.
Tried this on both the Forwarder & indexer without success, what am i missing ?

Props.conf
[source:://e:\trs\log\accountweb\aw*.log]
SEDCMD-SSN = s/SSN=\d{9})/SSN=xxxxxxxxx\1/g


Props.conf
[source:://e:\trs\log\accountweb\aw*.log]
TRANSFORMS-anonymize = ssn-anonymizer, ssnlookup-anonymizer

Transforms.conf:
[ssn-anonymizer]
REGEX = (?m)(^|)SSN=($|['])[0-9]{9}($|['])
FORMAT = $1SSN=#########'$2
DESTKEY = _raw
[ssnlookup-anonymizer]
REGEX = (?m)(^|)SSNLookup=($|['])[0-9]{9}($|['])
FORMAT = $1SSNLookup=#########'$2
DEST
KEY = _raw

0 Karma
Highlighted

Re: Mask SSN on forwarder/Indexer?

SplunkTrust
SplunkTrust

This:

[source:://e:\trs\log\accountweb\aw*.log]
SEDCMD-SSN = s/SSN=\d{9})/SSN=xxxxxxxxx\1/g

Should be this:

[source:://e:\trs\log\accountweb\aw*.log]
SEDCMD-SSN = s/SSN=\d{9}/SSN=xxxxxxxxx/g
Highlighted

Re: Mask SSN on forwarder/Indexer?

New Member

Tried this , but still not masking

0 Karma
Highlighted

Re: Mask SSN on forwarder/Indexer?

SplunkTrust
SplunkTrust

It needs to be on s heavy forwarder or the indexers. Where did you put it?

0 Karma
Highlighted

Re: Mask SSN on forwarder/Indexer?

New Member

On thge Indexer

0 Karma
Highlighted

Re: Mask SSN on forwarder/Indexer?

SplunkTrust
SplunkTrust

Did you reload your data? Will only apply to new data.

0 Karma