Getting Data In

Anonymize data by editing your own custom script

sarahh
Engager

May I know if there is any way to anonymise/mask the data in our search results by using our own custom commands, by editing our own custom script? For example, in the search results, I want to anonymise a certain interesting field by coding in my own custom script. Is it possible? Are there any guide to it? Thanks.

Tags (1)
0 Karma

kallu
Communicator

If you want to extend Splunk with your legacy scripts, maybe this example helps you to get started.
If you just want to anonymize your logs before sending them to some 3rd party, maybe scrub -cmd could do it for you without custom scripts?

None of these actually can hide your data that has been indexed by Splunk. These only manipulate search results. You can still dig out the original data using another search. If it is something really sensitive you should do the masking & hashing at indexing time. Not sure how/if custom code could be used in that case.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...