# Anonymize part of string

**URL:** <https://discuss.elastic.co/t/anonymize-part-of-string/345631>\
**Category:** Logstash\
**Tags:** transforms\
**Created:** [October 24, 2023, 11:42am UTC](https://discuss.elastic.co/t/anonymize-part-of-string/345631 "2023-10-24T11:42:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ddoroshenko](https://avatars.discourse-cdn.com/v4/letter/d/b9e5f3/32.png) [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Post date:** [October 24, 2023, 11:42am UTC](https://discuss.elastic.co/t/anonymize-part-of-string/345631/1 "2023-10-24T11:42:18Z")

</div>

Hi,

I have access logs which contains sensitive data

```auto
[2023-00-00T00:00:00.000] ... "GET /example.com/foo/bar?password=SecretPassword&user=UserName" ...

```

Is it possible to anonymize password value in that string?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 24, 2023, 12:09pm UTC](https://discuss.elastic.co/t/anonymize-part-of-string/345631/2 "2023-10-24T12:09:56Z")

</div>

> [@ddoroshenko](#):
>
> Is it possible to anonymize password value in that string?

The following `gsub` filter can do that:

```auto
filter {
    mutate {
        gsub => ["fieldName","password=(\S+)&user","password=REDACTED&user"]
    }
}

```

Where the `fieldName` is the field that has the following string:

```auto
/example.com/foo/bar?password=SecretPassword&user=UserName

```

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [October 26, 2023, 10:29am UTC](https://discuss.elastic.co/t/anonymize-part-of-string/345631/3 "2023-10-26T10:29:30Z")

</div>

On a non-elastic related note, using the URL to store secrets is **bad** idea, if at all possible I would advise you to have the application changed instead of only obfuscating the logs within elastic.

Couple of sources to help understand why this is a bad idea:

- [Information exposure through query strings in url | OWASP Foundation](https://owasp.org/www-community/vulnerabilities/Information_exposure_through_query_strings_in_url)
- [OWASP Top Ten 2017 | A3:2017-Sensitive Data Exposure | OWASP Foundation](https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure)
- [web application - Should sensitive data ever be passed in the query string? - Information Security Stack Exchange](https://security.stackexchange.com/questions/29598/should-sensitive-data-ever-be-passed-in-the-query-string)

---

<div class="post-metadata">

**Author:** ![ddoroshenko](https://avatars.discourse-cdn.com/v4/letter/d/b9e5f3/32.png) [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Post date:** [October 26, 2023, 12:30pm UTC](https://discuss.elastic.co/t/anonymize-part-of-string/345631/4 "2023-10-26T12:30:56Z")

</div>

@leandrojmp thank you for advice.

I've solved it with adding `processors` section into filebeat configuration

```auto
processors:
  - script:
      lang: javascript
      source: >
        function process(event) {
            event.Put("message, event.Get("message")
              .replace(/(password=)[set of symbols]+(&?), "$1HIDDEN$2")
              .replace(/(user=)[set of symbols]+(&?), "$1HIDDEN$2");
            return.event
        }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2023, 12:31pm UTC](https://discuss.elastic.co/t/anonymize-part-of-string/345631/5 "2023-11-23T12:31:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
