# Need help to understand SanitizeFieldNames

**URL:** <https://discuss.elastic.co/t/need-help-to-understand-sanitizefieldnames/224662>\
**Category:** APM\
**Tags:** dotnet\
**Created:** [March 23, 2020, 11:45am UTC](https://discuss.elastic.co/t/need-help-to-understand-sanitizefieldnames/224662 "2020-03-23T11:45:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Goulding](https://avatars.discourse-cdn.com/v4/letter/g/c5a1d2/32.png) [@Goulding](https://discuss.elastic.co/u/Goulding)\
**Post date:** [March 23, 2020, 11:45am UTC](https://discuss.elastic.co/t/need-help-to-understand-sanitizefieldnames/224662/1 "2020-03-23T11:45:20Z")

</div>

APM Server version: 7.4.2

APM Agent language and version: dotnet 1.4.0

Hi,  
I need help to understand the use of SanitizeFieldNames in APM.

If I want to make SanitizeFieldNames to work for a request header called "dontshowthisinapm", the only thing I should do is to add this field's name in the settings for ElasticApm:SanitizeFieldNames  
`(along with all the defaults "password", "passwd", "pwd", "secret", "*key", "*token*", "*session*", "*credit*", "*card*", "authorization", "set-cookie") ? `

Or do I have to do something more to make it work? I added this in the settings:

```auto
"ElasticApm": {
		"SecretToken": "verysecrettoken",
		"ServerUrls": "myfineserverurl",
		"ServiceName": "myfantasticservice",
		"TransactionSampleRate": 1.0,
		"SanitizeFieldNames": [
			"dontshowthisinapm",
			"password",
			"passwd",
			"pwd",
			"secret",
			"*key",
			"*token*",
			"*session*",
			"*credit*",
			"*card*",
			"authorization",
			"set-cookie"
		]
	}

```

The default fields are [REDACTED] in APM, but my new field dontshowthisinapm is not. It's still showing its secret content.

Can someone help me to clarify what I missed in the setup please? 🙂

---

<div class="post-metadata">

**Author:** ![GregKalapos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregkalapos/32/37205_2.png) [@GregKalapos](https://discuss.elastic.co/u/GregKalapos)\
**Post date:** [March 23, 2020, 12:28pm UTC](https://discuss.elastic.co/t/need-help-to-understand-sanitizefieldnames/224662/2 "2020-03-23T12:28:10Z")

</div>

Hi @Goulding, welcome here on discuss 👏

It should be a single comma separated string, like this (leaving out some of them in my sample):

```auto
"ElasticApm": {
		"SecretToken": "verysecrettoken",
		"ServerUrls": "myfineserverurl",
		"ServiceName": "myfantasticservice",
		"TransactionSampleRate": 1.0,
		"SanitizeFieldNames": "dontshowthisinapm, password, passwd, *key, *token*, set-cookie"
	}

```

---

<div class="post-metadata">

**Author:** ![Goulding](https://avatars.discourse-cdn.com/v4/letter/g/c5a1d2/32.png) [@Goulding](https://discuss.elastic.co/u/Goulding)\
**Post date:** [March 23, 2020, 3:07pm UTC](https://discuss.elastic.co/t/need-help-to-understand-sanitizefieldnames/224662/3 "2020-03-23T15:07:02Z")

</div>

Thanx a lot! Now it works! 🙂  
I have this in my configuration now:  
`"SanitizeFieldNames": "dontshowthisinapm, password, passwd, pwd, secret, *key, *token*, *session*, *credit*, *card*, authorization, set-cookie"`

But.. I discovered that it only works if I place the field dontshowthisinapm first in the string for SanitizeFieldNames. If I also put a field called password with a value in the header of the request, it's visible in APM with the content not redacted. It seems that the defaults isn't filtered out?

If I add another value dontshowthisinapm2 as a second parameter in SanitizeFieldNames it ignores that as well. It seems to me that it only handles the first parameter in SanitizeFieldNames? Or am I still doing something wrong with this configuration? 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2020, 11:07am UTC](https://discuss.elastic.co/t/need-help-to-understand-sanitizefieldnames/224662/4 "2020-04-13T11:07:04Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
