# How to mask card number of xml message

**URL:** <https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925>\
**Category:** Elasticsearch\
**Created:** [January 11, 2023, 12:42pm UTC](https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925 "2023-01-11T12:42:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anil0110](https://avatars.discourse-cdn.com/v4/letter/a/ce7236/32.png) [@Anil0110](https://discuss.elastic.co/u/Anil0110)\
**Post date:** [January 11, 2023, 12:42pm UTC](https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925/1 "2023-01-11T12:42:20Z")

</div>

Hello the requirement is we need to mask the cardnumber of xml message

our input message looks like :

message :  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f7876abd2919d2063c9d7c6c9a73e0198a2efd20.png)

output message expected

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/5/857efc3f1ba9f2cfe452d276efe968f08755ab21.png)

---

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [January 11, 2023, 4:50pm UTC](https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925/2 "2023-01-11T16:50:45Z")

</div>

Elasticsearch doesn't provide any functionality to mask or obfuscate a single line of your payload. However, there are few options to secure whole payload field itself, not sure how much of interest that will be for you.  
The options, however, include field level security, pseudonimization and or a combination of both.  
If you still want to mask a particular line in your event, you are in for a tedious ingest pipeline scripting.

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [January 11, 2023, 10:04pm UTC](https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925/3 "2023-01-11T22:04:04Z")

</div>

You might be able to use a [runtime field](https://www.elastic.co/guide/en/elasticsearch/reference/current/runtime.html) here, in combination with [field level security](https://www.elastic.co/guide/en/elasticsearch/reference/current/field-level-security.html) to show an masked output without needing to alter data, but...

1. runtime fields have overhead so this might not be ideal
2. I'm not 100% sure runtime fields work with field level security
  - I'd assume so, but I've never tested it

_ **Very big but:** _

1. There are very few legitimate reasons you should be sorting raw credit card data in the first place. There are a lot of standards/policies/regulations around this data. You should be asking yourself if your use-case _really_ needs to store the full raw credit card number in the first place. And if it _really_ does need to, you should be _really_ sure you're doing it correctly.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 11, 2023, 10:22pm UTC](https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925/4 "2023-01-11T22:22:19Z")

</div>

If you are parsing your XML message and have the `cardNumber` in a field, it is pretty easy to anonymize it, but how you do that depends on how you are parsing your message, if you are using Logstash or not for example.

If you are not parsing your XML message and have the entire XML data on a field, you may be able to anonymize it before ingesting if you are using Logstash or maybe if you are using a ingest pipeline.

The anonymization of the data needs to be done before ingesting.

How are you ingesting your data?

---

<div class="post-metadata">

**Author:** ![Anil0110](https://avatars.discourse-cdn.com/v4/letter/a/ce7236/32.png) [@Anil0110](https://discuss.elastic.co/u/Anil0110)\
**Post date:** [January 15, 2023, 7:19am UTC](https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925/5 "2023-01-15T07:19:47Z")

</div>

Dear Ayush,

Only need to mask card number value not the element

---

<div class="post-metadata">

**Author:** ![Ayush\_Mathur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayush_mathur/32/77134_2.png) [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Post date:** [January 16, 2023, 7:19am UTC](https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925/6 "2023-01-16T07:19:27Z")

</div>

@Anil0110 in that case, as I commented earlier and @leandrojmp has suggested, you can use ingest pipeline to obfuscate the data if you whole XML is residing in a separate field, generally named as "payload". You can then call this pipeline from filebeat based on condition that your "payload contains cardNumber".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2023, 7:20am UTC](https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925/7 "2023-02-13T07:20:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
