You need to use transforms.conf to mask the data, so that's not something you can do in the UI presently. However, you can create a configuration app and, now with Splunk 7.2+ you can upload both the props and transforms and install them to both Seach Head and indexers, via a new Splunk API call that applies cluster bundles to the indexers via the clustermaster. All that is done behind the scenes. Check this out: https://docs.splunk.com/Documentation/SplunkCloud/8.0.2006/User/PrivateApps
... View more