3 ms·
Ideally the data should be filtered before it gets to logging in the first place, but if not, you can add another layer of defense by employing censors: https
by wsargent 6y ago
Ideally the data should be filtered before it gets to logging in the first place, but if not, you can add another layer of defense by employing censors:
https://tersesystems.github.io/terse-logback/guide/censor/ https://tersesystems.github.io/terse-logback/guide/censor/
Or you can use logstash-logback-encoder, which has masking:
https://github.com/logstash/logstash-logback-encoder#masking https://github.com/logstash/logstash-logback-encoder#masking
- wsargent 6y agoThere's also Witchcraft Logging, which has the concept of "safe" parameters and is available in Go, Rust, and Clojure: https://docs.rs/witchcraft-log/0.3.0/witchcraft_log/ https://docs.rs/witchcraft-log/0.3.0/witchcraft_log/