Forum Discussion
Is there a way to mask JSESSIONID?
My understanding of Data Mask is for masking response only, not for request. Is it correct?
I tried to mask the JESSIONID value because I do not want it to show on the alerts and splunk log.
Thanks!!
2 Replies
- Vijith_182946
Cirrostratus
Hi, I would definitely look at this similar conversation, hope this will help.
https://devcentral.f5.com/questions/masking-jsessionid-with-asm
If this not solve the issue, i am just thinking of data guard with exception pattern but not sure though..
cheers,
- Hannes_Rapp
Nimbostratus
The first step to solve your issue is to determine what JSESSIONID is for your application - a Cookie, a Header, a Payload Parameter(POST) or a URI Parameter? JSESSIONID used to be a universal name for session cookies, but nowadays it's used in many different ways.
In any case, if that's a cookie which is inserted by BigIP, and is only significant for the balancing/persistency decisions in BigIP; it should not be a problem to use a substitution value. If that cookie has a significant function for the end-server or other middleware, there are more things to consider.
Your understanding about Data Guard is correct. It's only use is to mask the sensitive data values from the end-user, not from the back-end systems.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com