# Remove password but keep username in http authorization header

**URL:** <https://discuss.elastic.co/t/remove-password-but-keep-username-in-http-authorization-header/37415>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [December 16, 2015, 10:59pm UTC](https://discuss.elastic.co/t/remove-password-but-keep-username-in-http-authorization-header/37415 "2015-12-16T22:59:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![nradonicich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nradonicich/32/22843_2.png) [@nradonicich](https://discuss.elastic.co/u/nradonicich)\
**Post date:** [December 16, 2015, 10:59pm UTC](https://discuss.elastic.co/t/remove-password-but-keep-username-in-http-authorization-header/37415/1 "2015-12-16T22:59:08Z")

</div>

Is it possible to strip out the password from the authorization header but retain the username somehow? I use basic auth for some web apps and want to keep the username of who is accessing but strip out the password from being saved/sent over the wire more.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 17, 2015, 6:40pm UTC](https://discuss.elastic.co/t/remove-password-but-keep-username-in-http-authorization-header/37415/2 "2015-12-17T18:40:32Z")

</div>

No, this is currently not possible. Feel free to add an enhancement request to [github.com/elastic/beats](http://github.com/elastic/beats) or create a PR.

---

<div class="post-metadata">

**Author:** ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)\
**Post date:** [December 18, 2015, 4:03pm UTC](https://discuss.elastic.co/t/remove-password-but-keep-username-in-http-authorization-header/37415/3 "2015-12-18T16:03:24Z")

</div>

There is the [redact\_authorization](https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-configuration.html#_redact_authorization) configuration option that removes the entire header (Authorization and Proxy-Authorization), not only the password.

Additionally it is possible to censor all the passwords from the request URI and the attached form by using [hide\_keywords](https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-configuration.html#_hide_keywords) configuration option. We could extend this feature to censor also the headers. Please open a feature request [here](https://github.com/elastic/beats/issues).

---

<div class="post-metadata">

**Author:** ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)\
**Post date:** [December 18, 2015, 4:57pm UTC](https://discuss.elastic.co/t/remove-password-but-keep-username-in-http-authorization-header/37415/4 "2015-12-18T16:57:54Z")

</div>

Another option would be to use the [grok patterns from Logstash](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) to censor the password and keep the username from the Authorization header. You can configure Packetbeat to send the data compressed and encrypted to Logstash by configuring TLS. I hope this helps!

---

<div class="post-metadata">

**Author:** ![nradonicich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nradonicich/32/22843_2.png) [@nradonicich](https://discuss.elastic.co/u/nradonicich)\
**Post date:** [January 2, 2016, 10:26pm UTC](https://discuss.elastic.co/t/remove-password-but-keep-username-in-http-authorization-header/37415/5 "2016-01-02T22:26:30Z")

</div>

Thanks, this is what i ended up doing. I didn't test much but for completeness/efficiency (colon in password?) but here is for anyone else what i started with, most stolen from around the web that i forgot where i got it from.

filter {  
if [http][request\_headers][authorization] =~ /^Basic/ {  
grok {  
match =\> ["[http][request\_headers][authorization]", "Basic %{GREEDYDATA:b64}"]  
}  
ruby {  
init =\> "require 'base64'"  
code =\> "event['b64\_decoded'] = Base64.decode64(event['b64']) if event.include?('b64')"  
}  
mutate {  
gsub =\> ["b64\_decoded", ":.\*", ""]  
}  
mutate {  
update =\> { "[http][request\_headers][authorization]" =\> "%{b64\_decoded}" }  
remove\_field =\> ["b64\_decoded", "b64"]  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:57pm UTC](https://discuss.elastic.co/t/remove-password-but-keep-username-in-http-authorization-header/37415/6 "2017-07-05T21:57:08Z")

</div>


