# Logstash masking logs syntax

**URL:** <https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699>\
**Category:** Logstash\
**Created:** [February 16, 2023, 7:57am UTC](https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699 "2023-02-16T07:57:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![furkano](https://avatars.discourse-cdn.com/v4/letter/f/e9c0ed/32.png) [@furkano](https://discuss.elastic.co/u/furkano)\
**Post date:** [February 16, 2023, 7:57am UTC](https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699/1 "2023-02-16T07:57:37Z")

</div>

Hi,

I want to mask some logs in spesific fields, for example if end point ends with api or token i want to remove userKey messages from field ResponseMessage

But not whole field that i want to remove or mask, only the userKey message.

Is it possible to do it? userKey is not an field for our logs.

I wrote something like this but it's not working;

```auto
filter {
 if "PROD" in [tags] {
	
     {
   if "api","token" in [EndPoint]
 
 mutate {
 gsub => ["ResponseMessage","(?im)(\\?\"([\w\d]*?(encryptionKey|userKey)[\w\d]*?)\\?\"\:\\?\s\\?\")(.*?)(\\\"|\"|,|})", "\1***\5"]
 
   }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 20, 2023, 12:25am UTC](https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699/2 "2023-02-20T00:25:00Z")

</div>

> [@furkano](#):
>
> `if "api","token" in [EndPoint]`

What would you like that to mean?

---

<div class="post-metadata">

**Author:** ![furkano](https://avatars.discourse-cdn.com/v4/letter/f/e9c0ed/32.png) [@furkano](https://discuss.elastic.co/u/furkano)\
**Post date:** [February 20, 2023, 5:31am UTC](https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699/3 "2023-02-20T05:31:20Z")

</div>

Actually it was only for "api" , i used it for if there is any "api" value in EndPoint i wanted to filter for it

---

<div class="post-metadata">

**Author:** ![furkano](https://avatars.discourse-cdn.com/v4/letter/f/e9c0ed/32.png) [@furkano](https://discuss.elastic.co/u/furkano)\
**Post date:** [February 20, 2023, 5:32am UTC](https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699/4 "2023-02-20T05:32:58Z")

</div>

I want to use filter like this

> [@Find and replace string in \[message\] field](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319/5):
>
> You'd have to use a ruby filter for this.

"Is there a way i can do the following using logstash filters:  
I have an ID stored in a field example id: 123456789.  
I want to replace first 5 digits with an 'x'. so that id looks like, id:xxxxx6789.  
How can i do this in logstash filters?"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2023, 5:33am UTC](https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699/5 "2023-03-20T05:33:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
