Hi @gcusello, Thank your for reply. I want to masking data at search-time on Splunk Cloud. Example like this: [1] Enable role-based field filtering feature file: /opt/splunk/etc/system/local/limits.conf # [search] role_based_field_filtering = true [2] Config field filtering for user role (not support on UI, manual edit only), example role name is "staff" file: /opt/splunk/etc/system/local/authorize.conf # [role_staff] fieldFilter-host = SHA256 fieldFilter-_raw = s/output_mode=[^ ']+/output_mode=HIDDEN/g fieldFilterLimit = sourcetype::audittrail importRoles = user
... View more