Social Security Numbers (PII) data is found in log events, which is against company policy. SSN format is as follows: 123-44-5678.
Which configuration file and stanza pair will mask possible SSNs in the log events?
A . props.conf
[mask-SSN]
REX = (?ms)^(.)<[SSN>d{3}-?d{2}-?(d{4}.*)$ "
FORMAT = $1<SSN>###-##-$2
KEY = _raw
B . props.conf
[mask-SSN]
REGEX = (?ms)^(.)<[SSN>d{3}-?d{2}-?(d{4}.*)$ "
FORMAT = $1<SSN>###-##-$2
DEST_KEY = _raw
C . transforms.conf
[mask-SSN]
REX = (?ms)^(.)<[SSN>d{3}-?d{2}-?(d{4}.*)$ "
FORMAT = $1<SSN>###-##-$2
DEST_KEY = _raw
D . transforms.conf
[mask-SSN]
REGEX = (?ms)^(.)<[SSN>d{3}-?d{2}-?(d{4}.*)$ "
FORMAT = $1<SSN>###-##-$2
DEST_KEY = _raw
Answer: B
Explanation:
Reference: https://community.splunk.com/t5/Archive/How-to-mask-SSN-into-our-logs-going-into-Splunk/tdp/433035
Leave a Reply