Splunk Search

PII in Email

rclifford
New Member

Hi,

   How can I find PII data in our email dashboard. Thank you

Personally Identifiable Information DetectedDetects personally identifiable information (PII) in the form of payment card data in machine-generated data. Some systems or applications inadvertently include sensitive information in logs thus exposing it in unexpected ways.No specific data model: system log files, application log files, network traffic payloads, etc.
Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @rclifford,

No, this is specially for credit card patterns. 

If you can write Social Security numbers regex you can use regex command to filter and create an alert.

Please check below for regex command usage examples;

https://docs.splunk.com/Documentation/SplunkCloud/8.1.2011/SearchReference/Regex#Examples

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @rclifford,

You can take a look LUHN checker app.

https://splunkbase.splunk.com/app/2753/

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

rclifford
New Member

Hi,

  Thanks for this. Can it also be modified to look for Social Security numbers?

                                                     

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...