A Log4j2 Rewrite policy to mask sensitive data in XML and JSON.
Add the following dependency to the project:
Wrapper for one or more MaskPolicy elements.
Wrapper for one or more Converter elements.
Convert are used to transform the log4j2 Message
into string before masking and convert the masked string back to log4j2 Message
The Converter class must implement the MessageConverter
attribute | values | description | required |
className | Fully qualified class name | Specify formatter class | true |
<Converter className="com.mycompany.MyMessageConverter" />
<MaskPolicy type="JSON" enabled="true">
<Exclusion value="$.store.book[*].author" />
attribute | values | description | required |
type | XML/JSON | Specify the type of Masker | true |
enabled | true/false | Enable or disable the masking | false |
Wrapper for one or more Exlusion elements.
Specify the element that shouldn't be masked.
The value attribute can be a simple string or a path.
If a single string is specified, all the nodes/elements/attributes
having that string as key/name will not be masked.
attribute | MaskPolicyType | values | required |
value | JSON | String/JsonPath | true |
<MaskPolicy type="JSON" enabled="true">
<Exclusion value="$.name" />
attribute | values | description |
value | XPath | Specify the elements that shouldn't be masked |
<MaskPolicy type="XML" >
<Exclusion value="/customer/order[1]" />
Below is an example of log4j2 configuration file.
<?xml version="1.0" encoding="UTF-8"?>
<Configuration status="debug" packages="com.mariocairone.log4j2">
<Console name="Console" target="SYSTEM_OUT">
<PatternLayout pattern="[%-5level] %d{yyyy-MM-dd HH:mm:ss.SSS} [%t] %c{1} - %msg%n" />
<Rewrite name="REWRITE">
<AppenderRef ref="Console" />
<MaskPolicy type="JSON" enabled="true">
<Exclusion value="$.name" />
<Root level="debug" additivity="false">
<appender-ref ref="Console" />
Note: the package com.mariocairone.log4j2
must be added in the log4j2 configuration file.