# How to Handle Selective Masking and Reversible Encryption for PII in Elasticsearch Ingestion

**URL:** <https://discuss.elastic.co/t/how-to-handle-selective-masking-and-reversible-encryption-for-pii-in-elasticsearch-ingestion/379807>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 4, 2025, 10:24am UTC](https://discuss.elastic.co/t/how-to-handle-selective-masking-and-reversible-encryption-for-pii-in-elasticsearch-ingestion/379807 "2025-07-04T10:24:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Souvik\_Das](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/souvik_das/32/107606_2.png) [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Post date:** [July 4, 2025, 10:24am UTC](https://discuss.elastic.co/t/how-to-handle-selective-masking-and-reversible-encryption-for-pii-in-elasticsearch-ingestion/379807/1 "2025-07-04T10:24:25Z")

</div>

Hi Folks,

I’m working on a use case where we ingest API response payloads into the Elastic Stack (Logstash → Elasticsearch). The payload contains JSON data with a mix of important application-level information (like response codes/messages) and personally identifiable information (PII) such as:

- `idNumber`
- `emailAddress`
- `cellphoneNumber`
- `surname`
- `physicalAddrLine1`

The payload comes in as a long string, e.g.:

`BANKA formatted request with mapping: {<structured JSON with PII>}`

### **Our Objective:**

- Retain important fields like responseCode/message
- **Mask or anonymize PII fields**
- For some fields (like `idNumber`), we may need **reversible encryption** instead of irreversible hashing using the fingerprint filter plugin, to allow re-identification under secure conditions

Please let me know if this is achievable with Elastic Stack.

Kind regards,  
Souvik

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 4, 2025, 2:18pm UTC](https://discuss.elastic.co/t/how-to-handle-selective-masking-and-reversible-encryption-for-pii-in-elasticsearch-ingestion/379807/2 "2025-07-04T14:18:47Z")

</div>

Hi @Souvik_Das

Perhaps take a look at these 2 blogs to get some ideas

> **[Using NLP and Pattern Matching to Detect, Assess, and Redact PII in Logs -...](https://www.elastic.co/observability-labs/blog/pii-ner-regex-assess-redact-part-1)**
>
> How to detect and assess PII in your logs using Elasticsearch and NLP

> **[Using NLP and Pattern Matching to Detect, Assess, and Redact PII in Logs -...](https://www.elastic.co/observability-labs/blog/pii-ner-regex-assess-redact-part-2)**
>
> How to detect, assess, and redact PII in your logs using Elasticsearch, NLP and Pattern Matching

Structured / patterns are pretty easy to detect and Redact / mask...

Unstructured like address and Names may require the use of NLP.

With respect to field level 2 way encryption,  
Elasticsearch does not natively support that.

You will need to build that at your application layer (yes that can be done with some work ) or perhaps use a 3rd party solution.
