Splunk Search

PII Data scan

yuvrajsharma_13
Explorer

Need help to write a generic query to capture PII Data ( social security numbers / credit card numbers /  email addresses )  from  application log ?

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

There is no such thing as "generic PII data scan".

Firstly, you need to define what you want to find, then define how this data can be expressed, then you search for it.

And you'll always get false positives and false negatives. That's just how it is with automated searching for such loosely defined stuff.

The more precisely defined format, the better (like IBAN numbers).

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...