Dashboards & Visualizations

Mask password in XML at index time

mkarimi
Path Finder

I have an XML file that looks something like this:

<?xml version="1.0" encoding="utf-8"?>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
   <update_identity_request xmlns="">
     <firstName>test</firstName>
     <lastName>data</lastName>
     <preferredLanguage>en_US</preferredLanguage>
     <password>3bcgh014</password>
     <shipState>CA</shipState>
     <shipCountry>USA</shipCountry>
   </update_identity_request>
  </updateOIMIdentity>
 </soapenv:Body>
</soapenv:Envelope>

and i'm trying to mask the password. I have the following in transforms

[password-anonymizer]
REGEX = (?ms)^(.*\&lt;password&gt;)\w+(.*)$
FORMAT = $1##########$2
DEST_KEY = _raw

and also this in props.conf

[masks_password]
TRANSFORMS-anonymize = password-anonymizer

tested my regex in https://regex101.com/ and it seems to be working fine too.

1 Solution

woodcock
Esteemed Legend

Did you put both these files on every indexer and then restart Splunk on each one?
Also is masks_password the sourcetype of the events that you wish to modify? If not, you need to change the string in your stanza header of props.conf.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Did you put both these files on every indexer and then restart Splunk on each one?
Also is masks_password the sourcetype of the events that you wish to modify? If not, you need to change the string in your stanza header of props.conf.

0 Karma

mkarimi
Path Finder

hadn't restarted the indexer. thanks very much

0 Karma

nuaraujo
Path Finder

Hello guys,

your regex works really well if you don't use alphanumeric characters. Can you help me find a regex to use with a password that contains alphanumeric characters?

Thanks in advance.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...