# Anonymize some fields in specifc index

**URL:** https://discuss.elastic.co/t/anonymize-some-fields-in-specifc-index/125824
**Category:** Elasticsearch
**Created:** [March 27, 2018, 9:08pm UTC](https://discuss.elastic.co/t/anonymize-some-fields-in-specifc-index/125824 "2018-03-27T21:08:25Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![mlobo](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@mlobo](https://discuss.elastic.co/u/mlobo)
#### Post date: [March 27, 2018, 9:08pm UTC](https://discuss.elastic.co/t/anonymize-some-fields-in-specifc-index/125824/1 "2018-03-27T21:08:25Z")

</div>

Hi all,

I'd like to know if is possible in Elasticsearch to store some fields, in a specific index, anonymized.

So, for example, I'd like that for index named "index\_secret", the fields named "gender" and "religion", are stored anonymized in Elasticsearch.

I found this plugin [https://www.elastic.co/guide/en/logstash/5.3/plugins-filters-anonymize.html](https://www.elastic.co/guide/en/logstash/5.3/plugins-filters-anonymize.html) but it's not clear for me if I can tell to anonymized fields in one specific index.

Thank you for your time.

Regards,  
Marcos.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [March 27, 2018, 10:16pm UTC](https://discuss.elastic.co/t/anonymize-some-fields-in-specifc-index/125824/2 "2018-03-27T22:16:40Z")

</div>

> [@mlobo](#):
>
> I'd like that for index named "index\_secret", the fields named "gender" and "religion", are stored anonymized in Elasticsearch

It depends on what you mean by anonymized. If you mean pseudonymized, then there is a great [Elastic blog post](https://www.elastic.co/blog/gdpr-personal-data-pseudonymization-part-1) today that covers it. But for a field like gender, which could have a cardinality as low as two, unmasking a single value unmasks everything, so pseudonymization does not look like a good approach.

Be sure to check the note at the top of the documentation you linked to that points out the [fingerprint](https://www.elastic.co/guide/en/logstash/current/plugins-filters-fingerprint.html) filter is preferred to anonymize.

Another approach would be randomization. A simple ruby filter could randomly set the gender field to one of two values. But I am struggling to think of a use case, even for testing, where visualizing or analyzing random noise adds any value.

```auto
ruby { code => 'if rand <= 0.5 then event.set("gender", "M") else event.set("gender", "F") end ' }

```

So the third approach would be to delete the field 😃

All of this assumes you are doing the "anonymization" using logstash before ingesting the data into elasticsearch. If you want to do it for data already in an index that is a very different problem.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 24, 2018, 10:16pm UTC](https://discuss.elastic.co/t/anonymize-some-fields-in-specifc-index/125824/3 "2018-04-24T22:16:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
