Redact a log and follow it
Redact a log and follow it
Mask card numbers, addresses and emails in a log, keep the parts that still identify a row, and go on masking what the log gains as it grows. The masks are on redaction.
$ cat app.log
2026-09-27T09:00:01Z INFO GET /v2/users from 10.0.0.5 took 120ms
2026-09-27T09:00:04Z ERROR payment for bob@x.com failed: card 4111 1111 1111 1111 declined
2026-09-27T09:00:05Z INFO GET /v2/users from 10.0.0.7 took 95ms
Mask, keeping what identifies a row
Each masked character becomes one *, so every column after a match stays where it was. --keep
leaves the named slices standing: a card’s last four digits, an address’s first two octets, an
email’s domain.
$ trex redact '(\{card}:card | \I:ip | \E:email)' --keep 'card:last4, ip:octet1-2, email:domain' app.log
2026-09-27T09:00:01Z INFO GET /v2/users from 10.0**** took 120ms
2026-09-27T09:00:04Z ERROR payment for ****x.com failed: card ***************1111 declined
2026-09-27T09:00:05Z INFO GET /v2/users from 10.0**** took 95ms
--mask pseudonym writes a name such as IP_1 instead, the same name for the same value
wherever it occurs.
Mask the end of a log
--tail N masks and prints the last N lines alone, so nothing outside them reaches the output
unmasked:
$ trex redact '(\{card}:card | \I:ip | \E:email)' --keep 'card:last4, ip:octet1-2, email:domain' app.log --tail 1
2026-09-27T09:00:05Z INFO GET /v2/users from 10.0**** took 95ms
Follow it as it grows
--follow then masks what the log gains, line by line, until interrupted, and reads a log cut
shorter or rotated under its name from its start again:
trex redact '(\{card}:card | \I:ip | \E:email)' --keep 'card:last4, ip:octet1-2, email:domain' app.log --tail 0 --follow
Protect-TrexText '(\{card}:card | \I:ip | \E:email)' -Keep card:last4, ip:octet1-2, email:domain -Path ./app.log -Tail 0 -FollowIn Rust trex::follow::Follower hands back what each file gains, to redact as above
(following a file).