Skip to main content

elastic-pii-redacter

Did you find PII (Personally Identifiable Information) in your Elasticsearch indices that doesn’t belong there? This is the tool for you!

The elastic-pii-redacter can help you redact information from even Searchable Snapshot mounted indices. It works with deeply nested fields, too!

Client Configuration

The tool connects using the es_client Python module.

You can use command-line options, or a YAML configuration file to configure the client connection. If using a configuration file is desired, the configuration file structure requires elasticsearch at the root level as follows:

---
elasticsearch:
  client:
    hosts: https://10.11.12.13:9200
    cloud_id:
    request_timeout: 60
    verify_certs:
    ca_certs:
    client_cert:
    client_key:
  other_settings:
    username:
    password:
    api_key:
      id:
      api_key:
      token:

logging:
  loglevel: INFO
  logfile: /path/to/file.log
  logformat: default
  blacklist: []

REDACTIONS_FILE Configuration

NOTE: If, under forcemerge, only_expunge_deletes is True, any configured value for max_num_segments will be ignored, and only documents marked for delete will be cleared. It is important to note this distinction as the default behavior is to merge to 1 segment per shard.

---
redactions:
  - job_name_20240506_redact_hot:
      pattern: hot-*
      query: {'match': {'message': 'message1'}}
      fields: ['message']
      message: REDACTED
      expected_docs: 1
      restore_settings: {'index.routing.allocation.include._tier_preference': 'data_warm,data_hot,data_content'}
  - job_name_20240506_redact_cold:
      pattern: restored-cold-*
      query: {'match': {'nested.key': 'nested19'}}
      fields: ['nested.key']
      message: REDACTED
      expected_docs: 1
      restore_settings: {'index.routing.allocation.include._tier_preference': 'data_warm,data_hot,data_content'}
      forcemerge:
        max_num_segments: 1
  - job_name_20240506_redact_frozen:
      pattern: partial-frozen-*
      query: {'range': {'number': {'gte': 8, 'lte': 11}}}
      fields: ['deep.l1.l2.l3']
      message: REDACTED
      expected_docs: 4
      forcemerge:
        only_expunge_deletes: True

Metadata

Release files for elasticsearch-pii-redacter 1.11.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for elasticsearch-pii-redacter 1.11.0
File Size Uploaded
elasticsearch_pii_redacter-1.11.0.tar.gz 25.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for elasticsearch-pii-redacter 1.11.0
File Interpreter ABI Platform
elasticsearch_pii_redacter-1.11.0-py3-none-any.whl Python 3 none any Details

Total release size: 55.9 kB

Release files / elasticsearch_pii_redacter-1.11.0.tar.gz

Download URL elasticsearch_pii_redacter-1.11.0.tar.gz
Size 25.5 kB
Tags Source
SHA-256 checksum
How to use checksums
85e4ac66700b5a316d47fffe9f084c48fa0fcf29e50515f6aad2a0c908c3a56f
BLAKE2b-256 checksum
How to use checksums
14c922c314447000fe7e571e44b65ddb950de3ce291a63b8a302118895fb10da
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.12.2

Release files / elasticsearch_pii_redacter-1.11.0-py3-none-any.whl

Download URL elasticsearch_pii_redacter-1.11.0-py3-none-any.whl
Size 30.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
53a61f6fad7d1a6f7b53e0dc126dd011e9649af171488390c5fc1be940853973
BLAKE2b-256 checksum
How to use checksums
f7b7deef31c72ce05a042868e5c242f8efe0bb5b836cd1632946aee872ceff81
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.12.2

Release history Release notifications | RSS feed

This release

1.11.0 This release

2 release files

1.10.1

2 release files

1.10.0

2 release files

1.9.2

2 release files

1.9.1

2 release files

1.9.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page