LOG AND SUPPORT BUNDLE REDACTION

Support Bundle and Log Sanitizer

Replace secrets, email addresses, usernames, IP addresses, hostnames, WWNs, IQNs and MAC addresses with consistent placeholders before you share log text with a vendor, a forum or an AI tool.

Processed locally in your browser – this tool sends nothing anywhere. Automated redaction can miss things: review the output before sharing it with vendors or AI tools.

1. What to redact

Company, customer, project or person names. Matched as literal text, case-insensitive, anywhere in the log.

Any word starting with one of these (followed by more characters) is treated as a hostname. Use distinctive prefixes.

Added to the built-in list (com, net, org, local, lan, corp, internal and others) for FQDN detection.

2. Input log content

Plain text only. Compressed or binary files (.zip, .tgz, .evtx, .etl) must be extracted or converted to text first.

What gets replaced

  • Secrets [SECRET-n] / [KEY-n]: PEM private key blocks, Authorization: Bearer/Basic headers, JWTs, AWS access key IDs and secret keys, and values of keys such as password, pwd, secret, token, api_key, access_key, auth, credential and SNMP community in key=value, key: value, quoted, JSON, XML and --password value forms. The key name is kept; only the value is replaced. Credentials in URLs (scheme://user:pass@host) are replaced too.
  • Email addresses [EMAIL-n], including the local part.
  • Accounts and paths: DOMAIN\user, user= / username: / "user": / login= values and the name in C:\Users\name or /home/name become [USER-n]; domain SIDs (S-1-5-21-...) become [SID-n]; UNC paths (\\server\share) become [PATH-n].
  • Storage and network identifiers: iSCSI IQNs and EUIs [IQN-n]; WWNs/WWPNs in colon form or as 16 bare hex digits starting with 1, 2, 5 or C [WWN-n]; MAC addresses in colon, dash and Cisco dotted form [MAC-n]; IPv4 [IP-n] and IPv6 (full, compressed, link-local with zone, IPv4-mapped) [IPV6-n].
  • Hostnames [HOST-n]: FQDNs ending in a known or user-supplied suffix, names after keywords such as host=, server: or “on sqlprd01”, names matching your prefixes, and later bare mentions of a hostname already found.
  • Consistent mapping: the same original value always gets the same placeholder across the whole text, so you can still follow one host or one account through the log. The same MAC or WWN written in different formats maps to one placeholder.

What this tool does not catch

  • Free-text names of people, customers, companies or projects. Add them as custom terms.
  • Custom hostnames with no known domain suffix, no keyword before them and no prefix you supplied (for example a bare server name in a sentence), and hostnames after a keyword that contain no digit.
  • Secrets in unusual formats: values not attached to a recognised key name, secrets split across lines, cookies and session IDs, password hashes, connection strings with unusual key names, and short command-line flags such as -p value.
  • Data inside binary, compressed or encoded content (archives, event log files, base64 blobs other than recognised tokens).
  • Serial numbers, asset tags, NAA/LUN IDs, VM, datastore, pool or policy names, and customer or case IDs.

Over-masking is deliberate on the safe side: dotted numbers that look like IPv4 addresses (for example version strings such as 10.2.1.3) are masked as IPs, 16-digit hex or decimal values starting with 1, 2, 5 or C are masked as WWNs, and some ordinary values after key names such as auth_method= are masked as secrets. Loopback and unspecified addresses (127.0.0.1, 0.0.0.0, ::1) and netmasks starting with 255. are left unchanged.

Automated redaction is a starting point. Review and test the output before relying on it with production data. HNOrigin is not affiliated with or endorsed by Commvault, VMware, Microsoft, Cisco or Amazon Web Services. Product names are trademarks of their owners.

Scroll to Top