Support Bundle and Log Sanitizer
Replace secrets, email addresses, usernames, IP addresses, hostnames, WWNs, IQNs and MAC addresses with consistent placeholders before you share log text with a vendor, a forum or an AI tool.
1. What to redact
Company, customer, project or person names. Matched as literal text, case-insensitive, anywhere in the log.
Any word starting with one of these (followed by more characters) is treated as a hostname. Use distinctive prefixes.
Added to the built-in list (com, net, org, local, lan, corp, internal and others) for FQDN detection.
2. Input log content
Plain text only. Compressed or binary files (.zip, .tgz, .evtx, .etl) must be extracted or converted to text first.
What gets replaced
- Secrets
[SECRET-n]/[KEY-n]: PEM private key blocks,Authorization: Bearer/Basicheaders, JWTs, AWS access key IDs and secret keys, and values of keys such as password, pwd, secret, token, api_key, access_key, auth, credential and SNMP community inkey=value,key: value, quoted, JSON, XML and--password valueforms. The key name is kept; only the value is replaced. Credentials in URLs (scheme://user:pass@host) are replaced too. - Email addresses
[EMAIL-n], including the local part. - Accounts and paths:
DOMAIN\user,user=/username:/"user":/login=values and the name inC:\Users\nameor/home/namebecome[USER-n]; domain SIDs (S-1-5-21-...) become[SID-n]; UNC paths (\\server\share) become[PATH-n]. - Storage and network identifiers: iSCSI IQNs and EUIs
[IQN-n]; WWNs/WWPNs in colon form or as 16 bare hex digits starting with 1, 2, 5 or C[WWN-n]; MAC addresses in colon, dash and Cisco dotted form[MAC-n]; IPv4[IP-n]and IPv6 (full, compressed, link-local with zone, IPv4-mapped)[IPV6-n]. - Hostnames
[HOST-n]: FQDNs ending in a known or user-supplied suffix, names after keywords such ashost=,server:or “on sqlprd01”, names matching your prefixes, and later bare mentions of a hostname already found. - Consistent mapping: the same original value always gets the same placeholder across the whole text, so you can still follow one host or one account through the log. The same MAC or WWN written in different formats maps to one placeholder.
What this tool does not catch
- Free-text names of people, customers, companies or projects. Add them as custom terms.
- Custom hostnames with no known domain suffix, no keyword before them and no prefix you supplied (for example a bare server name in a sentence), and hostnames after a keyword that contain no digit.
- Secrets in unusual formats: values not attached to a recognised key name, secrets split across lines, cookies and session IDs, password hashes, connection strings with unusual key names, and short command-line flags such as
-p value. - Data inside binary, compressed or encoded content (archives, event log files, base64 blobs other than recognised tokens).
- Serial numbers, asset tags, NAA/LUN IDs, VM, datastore, pool or policy names, and customer or case IDs.
Over-masking is deliberate on the safe side: dotted numbers that look like IPv4 addresses (for example version strings such as 10.2.1.3) are masked as IPs, 16-digit hex or decimal values starting with 1, 2, 5 or C are masked as WWNs, and some ordinary values after key names such as auth_method= are masked as secrets. Loopback and unspecified addresses (127.0.0.1, 0.0.0.0, ::1) and netmasks starting with 255. are left unchanged.
Automated redaction is a starting point. Review and test the output before relying on it with production data. HNOrigin is not affiliated with or endorsed by Commvault, VMware, Microsoft, Cisco or Amazon Web Services. Product names are trademarks of their owners.