# What is the best practice to pseudonymize user data?

**URL:** https://discuss.elastic.co/t/what-is-the-best-practice-to-pseudonymize-user-data/252573
**Category:** Elastic Security
**Created:** [October 19, 2020, 3:21pm UTC](https://discuss.elastic.co/t/what-is-the-best-practice-to-pseudonymize-user-data/252573 "2020-10-19T15:21:58Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![elk51211](https://avatars.discourse-cdn.com/v4/letter/e/ccd318/32.png) [@elk51211](https://discuss.elastic.co/u/elk51211)
#### Post date: [October 19, 2020, 3:21pm UTC](https://discuss.elastic.co/t/what-is-the-best-practice-to-pseudonymize-user-data/252573/1 "2020-10-19T15:21:58Z")

</div>

What is the recommended approach to deal with logs to be as GDPR compliant as possible?  
I need to pseudonymize user data. The only resource I found is dated back to march of 2018 in this blog post: [https://www.elastic.co/de/blog/gdpr-personal-data-pseudonymization-part-1](https://www.elastic.co/de/blog/gdpr-personal-data-pseudonymization-part-1)

Is this still best practice? Can I use the fingerprint method within a beat instead of logstash, because I'm not using logstash right now and try to keep my stack as slim as possible.

Really looking forward to your answer and thanks a lot,  
Nils

---

<div class="post-metadata">

### Author: ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)
#### Post date: [November 3, 2020, 12:17am UTC](https://discuss.elastic.co/t/what-is-the-best-practice-to-pseudonymize-user-data/252573/2 "2020-11-03T00:17:16Z")

</div>

Hi @elk51211, I was curious and looked briefly into this but this isn't my area of expertise. It looks like there might have been some work in beats for a processor for this:

> **[Generate a fingerprint of an event | Filebeat Reference \[7.9\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/fingerprint.html)**

Outside of that I think there are discussions about accomplishing it on a technical level within ingest nodes but I don't think that is possible at the moment from some reading towards the bottom here:

> <https://github.com/elastic/elasticsearch/issues/16938>
>
> A potentially useful processor is one that can generate one or more "fingerprints" from an incoming document. This could aid in...

As for if this is the recommended approach to use a beats processor or logstash, that I cannot say for sure, someone else here might know more though.

---

<div class="post-metadata">

### Author: ![elk51211](https://avatars.discourse-cdn.com/v4/letter/e/ccd318/32.png) [@elk51211](https://discuss.elastic.co/u/elk51211)
#### Post date: [November 23, 2020, 8:47am UTC](https://discuss.elastic.co/t/what-is-the-best-practice-to-pseudonymize-user-data/252573/3 "2020-11-23T08:47:05Z")

</div>

Thanks for your opinion!

---

<div class="post-metadata">

### Author: ![elk51211](https://avatars.discourse-cdn.com/v4/letter/e/ccd318/32.png) [@elk51211](https://discuss.elastic.co/u/elk51211)
#### Post date: [November 23, 2020, 3:09pm UTC](https://discuss.elastic.co/t/what-is-the-best-practice-to-pseudonymize-user-data/252573/4 "2020-11-23T15:09:24Z")

</div>

I looked up the fingerprint beat solution. Unfortunately it does not offer an UUID Method. I need unique pseudo ids. Any idea?

---

<div class="post-metadata">

### Author: ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)
#### Post date: [November 23, 2020, 4:02pm UTC](https://discuss.elastic.co/t/what-is-the-best-practice-to-pseudonymize-user-data/252573/5 "2020-11-23T16:02:12Z")

</div>

I would open a github issue within the file beats repo as a feature request if it's missing something you need and they might be able to help you out:

> **[elastic/beats](https://github.com/elastic/beats/tree/master/filebeat)**
>
> :tropical\_fish: Beats - Lightweight shippers for Elasticsearch & Logstash - elastic/beats

---

<div class="post-metadata">

### Author: ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)
#### Post date: [November 26, 2020, 9:15pm UTC](https://discuss.elastic.co/t/what-is-the-best-practice-to-pseudonymize-user-data/252573/6 "2020-11-26T21:15:22Z")

</div>

@elk51211 Imho this is a good question. Also I've been waiting for a long time for part 2.. 🙂

> **[Protecting GDPR Personal Data with Pseudonymization](https://www.elastic.co/de/blog/gdpr-personal-data-pseudonymization-part-1)**
>
> GDPR lists pseudonymization as a technical measure that can be used to protect personal data. We explore an approach for implementing it in the Elastic Stack.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 4, 2022, 8:15am UTC](https://discuss.elastic.co/t/what-is-the-best-practice-to-pseudonymize-user-data/252573/7 "2022-11-04T08:15:44Z")

</div>


