# Logstash - obscure sensitive fields before putting them to the ES

**URL:** <https://discuss.elastic.co/t/logstash-obscure-sensitive-fields-before-putting-them-to-the-es/48253>\
**Category:** Logstash\
**Created:** [April 24, 2016, 12:02pm UTC](https://discuss.elastic.co/t/logstash-obscure-sensitive-fields-before-putting-them-to-the-es/48253 "2016-04-24T12:02:09Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![PavelPolyakov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pavelpolyakov/32/44810_2.png) [@PavelPolyakov](https://discuss.elastic.co/u/PavelPolyakov)\
**Post date:** [April 24, 2016, 12:02pm UTC](https://discuss.elastic.co/t/logstash-obscure-sensitive-fields-before-putting-them-to-the-es/48253/1 "2016-04-24T12:02:09Z")

</div>

Hi,

Recently I came up with the next question.

Imagine the next, I have an application which writes the logs. Each log is simple JSON object with the depth of N. Developers don't think about the values they put it the logs, we can find `password`, `IBAN`, `SSN` fields there on any of levels.

All the logs are put to the Redis queue, then logstash reads from Redis and puts them to the ES.

Is there any option right now, where I can configure logstash in the way, that it will parse the JSON object, iterate over it and will obscure the value of the "sensitive" field (meaning change 5 symbols to `*`, for example)?

I have tried to search something in this direction, but without any success right now.

Any thoughts?

Regards,

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2016, 5:24pm UTC](https://discuss.elastic.co/t/logstash-obscure-sensitive-fields-before-putting-them-to-the-es/48253/2 "2016-04-24T17:24:36Z")

</div>

I don't think there's a stock plugin for this. You could do it with a ruby filter and write a custom filter.

---

<div class="post-metadata">

**Author:** ![PavelPolyakov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pavelpolyakov/32/44810_2.png) [@PavelPolyakov](https://discuss.elastic.co/u/PavelPolyakov)\
**Post date:** [April 24, 2016, 6:14pm UTC](https://discuss.elastic.co/t/logstash-obscure-sensitive-fields-before-putting-them-to-the-es/48253/3 "2016-04-24T18:14:38Z")

</div>

Thanks, that looks like a possible solution.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 25, 2016, 2:52am UTC](https://discuss.elastic.co/t/logstash-obscure-sensitive-fields-before-putting-them-to-the-es/48253/4 "2016-04-25T02:52:33Z")

</div>

What about [https://www.elastic.co/guide/en/logstash/current/plugins-filters-anonymize.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-anonymize.html)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 25, 2016, 5:31am UTC](https://discuss.elastic.co/t/logstash-obscure-sensitive-fields-before-putting-them-to-the-es/48253/5 "2016-04-25T05:31:40Z")

</div>

> What about [https://www.elastic.co/guide/en/logstash/current/plugins-filters-anonymize.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-anonymize.html)

Ah, yes. If the name of the field(s) containing sensitive information is known then this is a good option.

---

<div class="post-metadata">

**Author:** ![PavelPolyakov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pavelpolyakov/32/44810_2.png) [@PavelPolyakov](https://discuss.elastic.co/u/PavelPolyakov)\
**Post date:** [April 25, 2016, 7:30am UTC](https://discuss.elastic.co/t/logstash-obscure-sensitive-fields-before-putting-them-to-the-es/48253/6 "2016-04-25T07:30:06Z")

</div>

regarding this plugin, I have several questions:

1. I haven't understood if this plugin checks only the first level of the log message for the fields with the given name, or it does it recursively?
2. As I understand, this plugin would replace the content of the field to the hash. Which is ok and is a solution, however, it's different from obscure method.

Thanks for pointing me to this plugin.

Regards,

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 25, 2016, 7:31am UTC](https://discuss.elastic.co/t/logstash-obscure-sensitive-fields-before-putting-them-to-the-es/48253/7 "2016-04-25T07:31:44Z")

</div>

1. What do you mean by levels? Logs don't usually have levels.
2. It's the same, you're replacing the data with something else. It's obscuring.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 25, 2016, 7:48am UTC](https://discuss.elastic.co/t/logstash-obscure-sensitive-fields-before-putting-them-to-the-es/48253/8 "2016-04-25T07:48:24Z")

</div>

The filter supports arrays of values but I don't think it supports nested fields, i.e. if you have

```auto
{
  "foo": {
    "bar": "baz"
  }
}

```

you can point if to `[foo][bar]` to obscure the "baz" string but you can't tell it to obscure `[foo]` and all subfields.

---

<div class="post-metadata">

**Author:** ![PavelPolyakov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pavelpolyakov/32/44810_2.png) [@PavelPolyakov](https://discuss.elastic.co/u/PavelPolyakov)\
**Post date:** [April 25, 2016, 10:31am UTC](https://discuss.elastic.co/t/logstash-obscure-sensitive-fields-before-putting-them-to-the-es/48253/9 "2016-04-25T10:31:36Z")

</div>

Yes, I meant searching for the keys inside the JSON object.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:00am UTC](https://discuss.elastic.co/t/logstash-obscure-sensitive-fields-before-putting-them-to-the-es/48253/10 "2017-07-06T05:00:45Z")

</div>


