Splunk Search

PII Data scan

yuvrajsharma_13
Explorer

Need help to write a generic query to capture PII Data ( social security numbers / credit card numbers /  email addresses )  from  application log ?

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

There is no such thing as "generic PII data scan".

Firstly, you need to define what you want to find, then define how this data can be expressed, then you search for it.

And you'll always get false positives and false negatives. That's just how it is with automated searching for such loosely defined stuff.

The more precisely defined format, the better (like IBAN numbers).

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...