Getting Data In

How to anonymize part of event

Starlette
Contributor

If I have data and I want to anonymize a part of an event (extracted field, let's say user),
I want to keep the original events in indexA and the anonymized events in indexB.

  • Does this affect my license? (doubled)
  • And if so, is it possible to route only the anonymized part to indexB and build searches for user and orig event in a way?
Tags (1)

Starlette
Contributor

Oke just wanted to make sure,,,( I hoped that you could also extracted a unique id and use this with a specific search/transaction)
so lets say that I cut the user part, and only index that one to indexB, and reconstruct this with searches over indexa en indexb on _time and "someid"

0 Karma

hazekamp
Builder

Starlette,

Collecting both original and anonymized events in separate index would effectively double licensing for those particular events. There is nothing I am aware of that would let you index only anonymized parts and reconstruct at search time.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...