Skip to content
Redact and follow logs

Redact a log and follow it

Redact a log and follow it

Mask card numbers, addresses and emails in a log, keep the parts that still identify a row, and go on masking what the log gains as it grows. The masks are on redaction.

$ cat app.log
2026-09-27T09:00:01Z INFO GET /v2/users from 10.0.0.5 took 120ms
2026-09-27T09:00:04Z ERROR payment for bob@x.com failed: card 4111 1111 1111 1111 declined
2026-09-27T09:00:05Z INFO GET /v2/users from 10.0.0.7 took 95ms

Mask, keeping what identifies a row

Each masked character becomes one *, so every column after a match stays where it was. --keep leaves the named slices standing: a card’s last four digits, an address’s first two octets, an email’s domain.

$ trex redact '(\{card}:card | \I:ip | \E:email)' --keep 'card:last4, ip:octet1-2, email:domain' app.log
2026-09-27T09:00:01Z INFO GET /v2/users from 10.0**** took 120ms
2026-09-27T09:00:04Z ERROR payment for ****x.com failed: card ***************1111 declined
2026-09-27T09:00:05Z INFO GET /v2/users from 10.0**** took 95ms

--mask pseudonym writes a name such as IP_1 instead, the same name for the same value wherever it occurs.

Mask the end of a log

--tail N masks and prints the last N lines alone, so nothing outside them reaches the output unmasked:

$ trex redact '(\{card}:card | \I:ip | \E:email)' --keep 'card:last4, ip:octet1-2, email:domain' app.log --tail 1
2026-09-27T09:00:05Z INFO GET /v2/users from 10.0**** took 95ms

Follow it as it grows

--follow then masks what the log gains, line by line, until interrupted, and reads a log cut shorter or rotated under its name from its start again:

trex redact '(\{card}:card | \I:ip | \E:email)' --keep 'card:last4, ip:octet1-2, email:domain' app.log --tail 0 --follow
Protect-TrexText '(\{card}:card | \I:ip | \E:email)' -Keep card:last4, ip:octet1-2, email:domain -Path ./app.log -Tail 0 -Follow

In Rust trex::follow::Follower hands back what each file gains, to redact as above (following a file).