Hi Everyone,
I am new at masking data and I want to mask a field wich corresponds to a TDC from a CSV file.
Here are sample of data that is already indexed in Splunk:
10,I,T10,**4152312098821234**,05/05/2018,12:43:12 a. m.," $1,000.00 "
19,R,T19,**4152312098348591**,05/05/2018,09:43:12 a. m.," $1,900.00 "
If you look the third field is the credit card number.
I have set the next things in **Transforms.conf**
[tdc-anonymizer]
REGEX = ^(?:[^,\n]*,){3}
FORMAT = \d{4}########\d{4}
DEST_KEY = _raw
I have set the next in **propf.conf**
[csv]
REPORT-anonymize = tdc-anonymizer
But it does not work, can anyone please help me ??
I have also try this pair of options in **transforms.conf** but do not work too
[tdc-anonymizer]
REGEX = ^(?:[^,\n]*,){3}$
FORMAT = $1\d{4}########\d{4}$2
DEST_KEY = _raw
[tdc-anonymizer]
REGEX = ^(?:[^,\n]*,){3}$(?P\d{16})
FORMAT = $1\d{4}########\d{4}$2
DEST_KEY = _raw
Thanks in advance
↧