![]() ![]() For any user you want to be able to disable PII masking, assign them to the PII_Unmask role in Splunk UBA.See Enable PII masking for all users in Splunk UBA. In Splunk UBA, verify that PII masking is enabled for all users in the system.For local users, follow the procedure in Allow local users to unmask PII in Splunk UBA. While this procedure also works for local users, it is not recommended because the PII_Unmask role has only a subset of the privileges in the User or Analyst role. This is the only way for non-local users to be able to unmask PII. Click OK to allow this user to unmask PII.Īllow non-local users to unmask PII in Splunk UBAįollow the procedure in this section to disable PII masking for all non-local users authenticating to Splunk UBA, including SSO or Splunk platform users.After logging in, they can select Unmask PII from the menu bar by clicking on their account name.Īdmin users have permissions to unmask PII by default and will not see the Allow PII Unmasking checkbox. To mask PII before the unmask time expires, refresh the browser. ![]() In both cases, the user can view PII for the configured Unmask Time (the default is 30 minutes). For users in the User, Analyst, or Content_Developer roles, click the checkbox in Allow PII Unmasking.Users assigned to the PII_Unmask role have permissions to unmask PII as given by the PII Unmask privilege in the role, even if the Allow PII Unmasking checkbox is not selected.Disable PII masking based on the user role:.Hover on the table row for the user you want to edit, then select the edit icon ( ) for that user.Verify that PII masking is enabled for all users in the system.When PII masking is disabled, PII is not masked. See Asset data fields in the Get Data into Splunk User Behavior Analytics manual.Īllow local users to unmask PII in Splunk UBAįollow the procedure in this section to disable PII masking for local users created in Splunk UBA. Mask the domain and login ID of the user's account. Mask the email address of the user's account. Mask the name of the country where the user resides. Mask the name of the state where the user resides. Mask the name of the city where the user resides. Mask the street name of the user's address. Mask the organizational unit (OU) of the user. You can select 15 minutes, 30 minutes, or 1 hour. The unmask time is the amount of time that users can view PII after unmasking PII. See Allow local users to unmask PII in Splunk UBA and Allow non-local users to unmask PII in Splunk UBA. Users can be allowed to unmask PII by being granted the specific privilege to do so, or by being assigned to a role with the privilege. In the PII Masking section, select Enable PII Masking.The data in the Splunk platform events is not masked, but you can use other access control mechanisms to prevent users without the proper access privileges from viewing PII in the Splunk platform.Įnable PII masking for all users in Splunk UBAĪs an administrator, you can enable PII masking for all users by performing the following procedure: Instead, to view the raw or triggering events from the Splunk platform, click view contributing events to view the events in the Splunk platform. Masking PII hides raw and triggering events from the Splunk platform. Masking PII affects only the display of information on Splunk UBA. Information sent automatically from Splunk UBA, such as threats and anomalies sent to Splunk Enterprise Security, ServiceNow, or email using the output connectors, is unaffected by PII masking. If you send a threat email while PII is masked, the PII is masked in the email. If you export or download dashboard information while PII is masked, the PII is masked in the downloaded information. Administrators can mask or unmask PII for all users or specific users.Įnabling PII masking in Splunk UBA causes the name, employee ID number, telephone number, email address, and user name (login ID) of each user in Splunk UBA to be replaced with a string of characters. To share information in Splunk UBA without disclosing personally identifiable information (PII), you can mask PII in Splunk UBA. Mask personally-identifiable information in Splunk UBA ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |