# Masking logic is not working

**URL:** <https://discuss.elastic.co/t/masking-logic-is-not-working/261827>\
**Category:** Logstash\
**Created:** [January 21, 2021, 4:45pm UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827 "2021-01-21T16:45:13Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![shree2](https://avatars.discourse-cdn.com/v4/letter/s/dbc845/32.png) [@shree2](https://discuss.elastic.co/u/shree2)\
**Post date:** [January 21, 2021, 4:45pm UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827/1 "2021-01-21T16:45:14Z")

</div>

Hi,

I want to mask the few fields input is coming from json . Please find the configuration below.  
input  
{  
file  
{  
path =\> "xxx/sample.log"  
}  
}  
filter  
{  
mutate  
{  
gsub =\> ["message", "PASSWORD:((?=._[a-z])(?=._[A-Z])(?=#._\d)(?=._[#@!%\*?&])[a-zA-Z\d@!%_?#&]{8,})", " **PASSWORD**",  
"message", "PIN:(\d{4})", "PIN\*\*\*\*\*",  
"message", "WEIGHT:[0-9]{2,3}", "WEIGHT_\*\*\*" ]  
}  
json  
{  
source =\> "message"  
}  
}  
output  
{  
elasticsearch  
{  
hosts =\> ["localhost:9200"]  
index =\> "patternmasking"  
}  
}

After running logstash iam getting the output of json without masking  
This is my json input  
{"PASSWORD":"Qwerty@123","PIN":1234,"WEIGHT":42}

Getting output `like this`  
{  
"host" =\> "host",  
"@version" =\> "1",  
"message" =\> "{"PASSWORD":"Qwerty@123","PIN":1234,"WEIGHT":42}\r",  
"WEIGHT" =\> 42,  
"@timestamp" =\> 2021-01-21T16:42:41.649Z,  
"PIN" =\> 1234,  
"PASSWORD" =\> "Qwerty@123"  
}

Can you find guide me how to mask those fields.

Thanks,  
Shree

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 21, 2021, 5:02pm UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827/2 "2021-01-21T17:02:58Z")

</div>

I would suggest doing the masking after parsing the JSON, but if you want to do it before the gsub patterns would have to result in valid JSON, so something like

```
"message", '"PIN": \d{4}', '"PIN": " ****"'
```

---

<div class="post-metadata">

**Author:** ![shree2](https://avatars.discourse-cdn.com/v4/letter/s/dbc845/32.png) [@shree2](https://discuss.elastic.co/u/shree2)\
**Post date:** [January 22, 2021, 7:08am UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827/3 "2021-01-22T07:08:55Z")

</div>

Hi,

I tried parsing json first then mutate gsub even though it's not masking, resulting valid json output.

input  
{  
}  
filter  
{  
json  
{  
source =\> "message"  
}  
mutate  
{  
gsub =\> [ ```  
"message", '"PIN": \d{4}', '"PIN": "\*\*\*\*"'

```auto
}
}
output
{
}

output:
{
           "PIN" => 1234,
       "message" => "{\"PIN\":1234}\r",
    "@timestamp" => 2021-01-22T07:05:04.730Z,
      "@version" => "1",
          "host" => "host"
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 22, 2021, 5:35pm UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827/4 "2021-01-22T17:35:31Z")

</div>

If you are going to parse the JSON before doing the mutates then you need to mutate the parsed fields, not the [message] field.

---

<div class="post-metadata">

**Author:** ![shree2](https://avatars.discourse-cdn.com/v4/letter/s/dbc845/32.png) [@shree2](https://discuss.elastic.co/u/shree2)\
**Post date:** [January 22, 2021, 5:53pm UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827/5 "2021-01-22T17:53:25Z")

</div>

You mean like this.  
mutate  
{  
gsub =\> [ ```  
'"PIN": \d{4}', '"PIN": "\*\*\*\*"'

Copy to clipboard

```auto
}

```

---

<div class="post-metadata">

**Author:** ![shree2](https://avatars.discourse-cdn.com/v4/letter/s/dbc845/32.png) [@shree2](https://discuss.elastic.co/u/shree2)\
**Post date:** [January 22, 2021, 5:54pm UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827/6 "2021-01-22T17:54:03Z")

</div>

mutate  
{  
gsub =\> [  
'"PIN": \d{4}', '"PIN": "\*\*\*\*"'

}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 22, 2021, 6:56pm UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827/7 "2021-01-22T18:56:15Z")

</div>

No, more like

```
mutate { convert => { "PIN" => "string" } }
mutate { gsub => ["PIN", "\d{4}", " ****"] }
```

---

<div class="post-metadata">

**Author:** ![shree2](https://avatars.discourse-cdn.com/v4/letter/s/dbc845/32.png) [@shree2](https://discuss.elastic.co/u/shree2)\
**Post date:** [January 24, 2021, 3:35pm UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827/8 "2021-01-24T15:35:21Z")

</div>

Hi,

I tried the same. But output is not masking.  
Getting output like this.  
{  
"message" =\> "{"PIN":1234}\r",  
"PIN" =\> 1234,  
"@version" =\> "1",  
"@timestamp" =\> 2021-01-24T15:33:54.686Z,  
"host" =\> "host"  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 24, 2021, 4:05pm UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827/9 "2021-01-24T16:05:44Z")

</div>

> [@shree2](#):
>
> "PIN" =\> 1234,

PIN in an integer there, not a string, so clearly you have not applied the filters I suggested.

---

<div class="post-metadata">

**Author:** ![shree2](https://avatars.discourse-cdn.com/v4/letter/s/dbc845/32.png) [@shree2](https://discuss.elastic.co/u/shree2)\
**Post date:** [January 25, 2021, 4:52am UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827/10 "2021-01-25T04:52:09Z")

</div>

Hi,

Here is the filter part which i parsed.

mutate  
{  
gsub =\> ['"PIN"', '"\d{4}"', "\*\*\*\*"]

}

---

<div class="post-metadata">

**Author:** ![shree2](https://avatars.discourse-cdn.com/v4/letter/s/dbc845/32.png) [@shree2](https://discuss.elastic.co/u/shree2)\
**Post date:** [January 29, 2021, 3:31pm UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827/11 "2021-01-29T15:31:49Z")

</div>

Hi,

Any solution?? Waiting for the response.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2021, 3:32pm UTC](https://discuss.elastic.co/t/masking-logic-is-not-working/261827/12 "2021-02-26T15:32:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
