Splunk Search

PII Data scan


Need help to write a generic query to capture PII Data ( social security numbers / credit card numbers /  email addresses )  from  application log ?

Labels (1)
0 Karma


There is no such thing as "generic PII data scan".

Firstly, you need to define what you want to find, then define how this data can be expressed, then you search for it.

And you'll always get false positives and false negatives. That's just how it is with automated searching for such loosely defined stuff.

The more precisely defined format, the better (like IBAN numbers).

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...