# Elastic APM sanitization on message body

**URL:** <https://discuss.elastic.co/t/elastic-apm-sanitization-on-message-body/240913>\
**Category:** APM\
**Created:** [July 13, 2020, 7:42am UTC](https://discuss.elastic.co/t/elastic-apm-sanitization-on-message-body/240913 "2020-07-13T07:42:05Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ali\_Nazemian](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@Ali\_Nazemian](https://discuss.elastic.co/u/Ali_Nazemian)\
**Post date:** [July 13, 2020, 7:42am UTC](https://discuss.elastic.co/t/elastic-apm-sanitization-on-message-body/240913/1 "2020-07-13T07:42:05Z")

</div>

We are using Elastic APM from Elasticsearch 7.8 with java agent. We would like to capture HTTP message body. However, it does not work as expected.

First, I'd expect that the sanitization can ensure a field would not be indexed if it contains the specified pattern in the property name. However, I can see that the sensitive value is presented in the `http.request.body.original`. But some other fields such as `http.request.headers.Authorization` are truly redacted. This shows that the sanitization configured properly, but for some reason, it does not work on the message body. Perhaps it expects the field name and due to the following issue, it hasn't been extracted.

Second, I can see that the entire message in the body is shown as a single value (the entire JSON object is stored as is and hasn't been indexed). This means I have got the following json value:

```
{
  "email": "test@abc.com",
  "password": "xxxxx"
}

```

Whereas, I expected to have a separate value for email and password (redacted). Am I missing something here?

---

<div class="post-metadata">

**Author:** ![Eyal\_Koren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eyal_koren/32/36830_2.png) [@Eyal\_Koren](https://discuss.elastic.co/u/Eyal_Koren)\
**Post date:** [July 13, 2020, 8:12am UTC](https://discuss.elastic.co/t/elastic-apm-sanitization-on-message-body/240913/2 "2020-07-13T08:12:25Z")

</div>

The agent captures request body as string, it doesn't attempt to parse it according to any specific schema. Therefore, it would not index JSON-fields and similarly can't sanitize for specific fields.

You should be able to achieve what you want by using [ingest node pipelines](https://www.elastic.co/guide/en/apm/server/7.8/configuring-ingest-node.html), specifically using the [JSON processor](https://www.elastic.co/guide/en/elasticsearch/reference/7.8/json-processor.html#json-processor).

I hope this helps.

---

<div class="post-metadata">

**Author:** ![Ali\_Nazemian](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@Ali\_Nazemian](https://discuss.elastic.co/u/Ali_Nazemian)\
**Post date:** [July 13, 2020, 8:27am UTC](https://discuss.elastic.co/t/elastic-apm-sanitization-on-message-body/240913/3 "2020-07-13T08:27:02Z")

</div>

Do I need to apply sanitization also as an additional processor? Does sanitization happen at the agent level or the server does the magic?

Moreover, we are using Elastic Cloud and I couldn't find a way to add a new pipeline to APM server. Is this only achievable in the self-hosted version?

---

<div class="post-metadata">

**Author:** ![Eyal\_Koren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eyal_koren/32/36830_2.png) [@Eyal\_Koren](https://discuss.elastic.co/u/Eyal_Koren)\
**Post date:** [July 13, 2020, 12:38pm UTC](https://discuss.elastic.co/t/elastic-apm-sanitization-on-message-body/240913/4 "2020-07-13T12:38:02Z")

</div>

The sanitation you see in agent configuration is done by agents. You need to handle that through processors, however, not necessarily you need more than one. From looking at the JSON processor, it seems you should be able to pick only the fields you want in the first place.

---

<div class="post-metadata">

**Author:** ![Ali\_Nazemian](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@Ali\_Nazemian](https://discuss.elastic.co/u/Ali_Nazemian)\
**Post date:** [July 13, 2020, 1:51pm UTC](https://discuss.elastic.co/t/elastic-apm-sanitization-on-message-body/240913/5 "2020-07-13T13:51:29Z")

</div>

Thanks. I am not sure how I can use JSON processor with a condition to skip a field if it matches a certain pattern. The issue with JSON processor is I can only have a condition on the input, but what I am looking for is a condition on the output. For example in the shared example, I would like to only skip `password`. I still would like to keep the email address.

---

<div class="post-metadata">

**Author:** ![gil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gil/32/41911_2.png) [@gil](https://discuss.elastic.co/u/gil)\
**Post date:** [July 13, 2020, 8:56pm UTC](https://discuss.elastic.co/t/elastic-apm-sanitization-on-message-body/240913/6 "2020-07-13T20:56:03Z")

</div>

> [@Ali\_Nazemian](#):
>
> Moreover, we are using Elastic Cloud and I couldn't find a way to add a new pipeline to APM server. Is this only achievable in the self-hosted version?

This can be accomplished Elastic Cloud by editing the `apm` processing pipeline that is always deployed there. This can be done via the UI at `<kibana_url>/app/kibana#/management/elasticsearch/ingest_pipelines?pipeline=apm` or via the standard kibana APIs.

> [@Ali\_Nazemian](#):
>
> Thanks. I am not sure how I can use JSON processor with a condition to skip a field if it matches a certain pattern. The issue with JSON processor is I can only have a condition on the input, but what I am looking for is a condition on the output. For example in the shared example, I would like to only skip `password` . I still would like to keep the email address.

Here is a complete example that I believe can accomplish what you have in mind:

```auto
POST /_ingest/pipeline/_simulate
{
  "pipeline": {
    "description": "redact http.request.body.original.password",
    "processors": [
      {
        "json": {
          "field": "http.request.body.original",
          "target_field": "http.request.body.original_json",
          "ignore_failure": true
        }
      },
      {
        "remove": {
          "field": "http.request.body.original",
          "if": "ctx?.http?.request?.body?.original_json != null",
          "ignore_failure": true
        }
      },
      {
        "set": {
          "field": "http.request.body.original_json.password",
          "value": "[redacted]",
          "if": "ctx?.http?.request?.body?.original_json != null"
        }
      }
    ]
  },
  "docs": [
    {
      "_source": {
        "http": {
          "request": {
            "body": {
              "original": """{"email": "test@abc.com", "password": "itsasecret"}"""
            }
          }
        }
      }
    },
    {
      "_source": {
        "nobody": true
      }
    },
    {
      "_source": {
        "http": {
          "request": {
            "body": {
              "original": """["invalid json" """
            }
          }
        }
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![Ali\_Nazemian](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@Ali\_Nazemian](https://discuss.elastic.co/u/Ali_Nazemian)\
**Post date:** [July 15, 2020, 3:14am UTC](https://discuss.elastic.co/t/elastic-apm-sanitization-on-message-body/240913/7 "2020-07-15T03:14:34Z")

</div>

Thanks. So what you are suggesting is to update the 'apm' pipeline and register the new processor. Do I need to restart the APM server or it will be loaded dynamically?

---

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [July 15, 2020, 5:07am UTC](https://discuss.elastic.co/t/elastic-apm-sanitization-on-message-body/240913/8 "2020-07-15T05:07:48Z")

</div>

It is not necessary to restart anything. Once you have updated the pipeline in Elasticsearch, any new data that APM Server sends to Elasticsearch will be run through the updated pipeline.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2020, 1:07am UTC](https://discuss.elastic.co/t/elastic-apm-sanitization-on-message-body/240913/9 "2020-08-05T01:07:52Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
