<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GLU Security &#8211; GLU Global</title>
	<atom:link href="https://glu.global/article-categories/glu-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://glu.global</link>
	<description>Innovation at Speed</description>
	<lastBuildDate>Wed, 25 Sep 2024 06:13:40 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://glu.global/wp-content/uploads/2022/01/cropped-favicon-1-32x32.png</url>
	<title>GLU Security &#8211; GLU Global</title>
	<link>https://glu.global</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>VAULTS</title>
		<link>https://glu.global/glu-guide/vaults/</link>
		
		<dc:creator><![CDATA[Richard Price]]></dc:creator>
		<pubDate>Wed, 18 Sep 2024 12:13:58 +0000</pubDate>
				<guid isPermaLink="false">https://glu.global/?post_type=ht_kb&#038;p=7278</guid>

					<description><![CDATA[What is VAULTs It is possible to store credentials in an external PAM (Privileged Access Management) environment and have the GLU.Engines collect the credentials at the time of start up. Integration to the following PAM systems are supported Please contact GLU Support for the details on how to configure the each PAM system in the [&#8230;]]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading"><strong>What is VAULTs</strong></h2>



<p>It is possible to store credentials in an external PAM (Privileged Access Management) environment and have the GLU.Engines collect the credentials at the time of start up.</p>



<p>Integration to the following PAM systems are supported</p>



<ul class="wp-block-list">
<li>AWS secrets</li>



<li>Azure Key Vault</li>



<li>HashiCorp Vault</li>
</ul>



<p>Please contact GLU Support for the details on how to configure the each PAM system in the start up scripts. </p>



<h2 class="wp-block-heading"><strong>Connectors Secure Credential Storage</strong></h2>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="671" height="434" data-id="7302" src="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-13.58.13-1.png" alt="" class="wp-image-7302" srcset="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-13.58.13-1.png 671w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-13.58.13-1-300x194.png 300w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-13.58.13-1-50x32.png 50w" sizes="(max-width: 671px) 100vw, 671px" /></figure>
</figure>



<p>In the connector environment settings, the Vault option allows you to securely store and manage sensitive information such as usernames and passwords. Here is how you can use the Vault flags for each field:</p>



<h2 class="wp-block-heading"><strong>Connectors Secure Username Vault Flag</strong></h2>



<p>1. <strong>Purpose</strong>: When enabled, this flag ensures that the username for the database connection is securely stored and retrieved from a VAULT, rather than being entered manually and stored in a potentially insecure manner.</p>



<p>2. <strong>How to Enable</strong>:</p>



<p>• Toggle the Vault switch next to the username field to “ON”.</p>



<p>• The VAULT secret-name that holds the username will be presented in the build manager once the GLU.Engine is built. If the secret is stored in the configured VAULT it will be picked up and used by the GLU.Engine.</p>



<p>• Once enabled, the username will be dynamically retrieved from the VAULT at the point the GLU.Engine is run and used in the execution of the connection process.</p>



<h2 class="wp-block-heading"><strong>Connectors Secure Password Vault Flag</strong></h2>



<p>1. <strong>Purpose</strong>: Similar to the username, this flag secures the storage of the password used for the database connection.</p>



<p>2. <strong>How to Enable</strong>:</p>



<p>• Toggle the Vault switch next to the password field to “ON”.</p>



<p>• Enter the VAULT secret name for the password in the password field. Ensure this secret is already present in the VAULT.</p>



<p>• The password will be used from VAULT when needed for authentication.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img decoding="async" width="681" height="397" data-id="7304" src="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-13.58.29-1.png" alt="" class="wp-image-7304" srcset="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-13.58.29-1.png 681w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-13.58.29-1-300x175.png 300w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-13.58.29-1-50x29.png 50w" sizes="(max-width: 681px) 100vw, 681px" /></figure>
</figure>



<p>S<strong>ecure Storage of SSL Credentials using Vault</strong></p>



<p>The Vault flags in the connector environment settings facilitate the secure management of SSL credentials by storing these sensitive details in VAULT. Here’s how to configure each section:</p>



<h2 class="wp-block-heading"><strong>Connectors Secure Key Store</strong></h2>



<p>1. <strong>Purpose</strong>: The Key Store contains private keys and associated certificates necessary for SSL connections.</p>



<p>2. <strong>Vault Flag</strong>:</p>



<p>• <strong>How to Enable</strong>: Toggle the Vault switch to “ON” for the Key Store password.</p>



<p>• <strong>Functionality</strong>: When enabled, this flag ensures that the password for the Key Store is fetched from VAULT.  Password will be automatically fetched during runtime of the GLU.Engine.</p>



<h2 class="wp-block-heading"><strong>Connectors Secure Trust Store</strong></h2>



<p>1. <strong>Purpose</strong>: The Trust Store holds certificates from trusted Certificate Authorities (CAs). These certificates are used to verify the identity of counterparties in SSL transactions.</p>



<p>2. <strong>Vault Flag</strong>:</p>



<p>• <strong>How to Enable</strong>: Toggle the Vault switch to “ON” for the Trust Store password.</p>



<p>• <strong>Functionality</strong>: Similar to the Key Store, enabling this flag secures the Trust Store password in the VAULT. Trust store password will be automatically fetched during runtime of the GLU.Engine.</p>



<h2 class="wp-block-heading has-medium-font-size"><strong>Global variable</strong></h2>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img decoding="async" width="451" height="550" data-id="7325" src="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-19-at-12.32.03.png" alt="" class="wp-image-7325" srcset="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-19-at-12.32.03.png 451w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-19-at-12.32.03-246x300.png 246w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-19-at-12.32.03-41x50.png 41w" sizes="(max-width: 451px) 100vw, 451px" /></figure>
</figure>



<p>The Vault Switch allows you to determine whether a specific variable&#8217;s value will be stored in a secure vault (e.g., <strong>Azure Key Vault</strong> or <strong>AWS Secrets Manager</strong>) for each environment. This is crucial for protecting sensitive data such as API keys, passwords, and other credentials.</p>



<h3 class="wp-block-heading">Key Components:</h3>



<p><strong>Name Field</strong>:</p>



<ol class="wp-block-list">
<li></li>
</ol>



<ul class="wp-block-list">
<li>Specifies the variable name. In this example, the variable is named <code>pinToAllTheMoney</code>.</li>



<li>The variable name for a global variable will become the <strong>Secret-name</strong> as used in the PAM.</li>
</ul>



<p><strong>Encrypted Checkbox</strong>:</p>



<ol class="wp-block-list">
<li></li>
</ol>



<ul class="wp-block-list">
<li>When selected, the value of the variable will be encrypted only for variables which are stores in GLU.Ware if the variable value is stored in a PAM it will <span style="text-decoration: underline;">not</span> be encrypted.</li>
</ul>



<p><strong>Vault Switch</strong>:</p>



<ol class="wp-block-list">
<li></li>
</ol>



<ul class="wp-block-list">
<li>The <strong>Vault Switch</strong> column on the right allows you to specify whether the variable for a particular environment will be retrieved from a PAM (such as <strong>Azure Key Vault</strong> or <strong>AWS Secrets Manager</strong>).</li>



<li><strong>Vault On</strong>: When the switch is enabled (checked), the variable value for that environment will be  retrieved from the vault.</li>



<li><strong>Vault Off</strong>: When the switch is disabled (unchecked), the variable value will <span style="text-decoration: underline;">not</span> be retrieved from a vault, and the value on the dialogue box will be used.</li>
</ul>



<h3 class="wp-block-heading">How to Use the Vault Switch:</h3>



<ul class="wp-block-list">
<li>For each environment where you need enhanced security, toggle the vault switch <strong>on</strong>. This ensures that the variable&#8217;s value will be retrieved from the vault at runtime.</li>



<li>If the switch is <strong>off</strong>, the value will not be stored in the vault, and the value stored in GLU.Ware as entered in the dialogue box will be used.</li>
</ul>



<ol class="wp-block-list">
<li><strong>Submit Changes</strong>:</li>
</ol>



<ul class="wp-block-list">
<li>Once you have configured the vault settings for each environment, click <strong>Submit</strong> to save your changes. Refer to section &#8220;Build Manager &#8211; Getting the <em><strong>Secret-name</strong></em> for the VAULT&#8221; to understand how to retrieve a list go <em><strong>Secret-name</strong></em> &#8216;s which need to go in the PAM.</li>
</ul>



<h3 class="wp-block-heading">Best Practices for Using Vault Switch:</h3>



<ul class="wp-block-list">
<li><strong>Sensitive Data</strong>: Always enable the vault switch for environments where the variable holds sensitive information (e.g., passwords, API tokens). This prevents the exposure of secrets in less secure storage locations.</li>



<li><strong>Consistency</strong>: Use the same vault provider (Azure Key Vault, AWS Secrets) across all production environments for consistency and easier management.</li>



<li><strong>Testing</strong>: In testing environments, you may choose to store the variables outside of the vault if the data isn&#8217;t sensitive. However, always ensure that sensitive data in production environments is secured in the vault.</li>
</ul>



<h3 class="wp-block-heading">Example:</h3>



<p>In the screenshot example:</p>



<ul class="wp-block-list">
<li>The variable <code>pinToAllTheMoney</code> is defined for various environments.</li>



<li>To secure this sensitive PIN in production environments, toggle the <strong>Vault</strong> switch <strong>on</strong> for environments like &#8220;EN10-production&#8221; and &#8220;Production&#8221;.</li>



<li>For non-sensitive environments (e.g., &#8220;Voucher Test&#8221;), you may choose to leave the vault switch <strong>off</strong>.</li>
</ul>



<p>By following these steps, you ensure that sensitive data is stored securely in the vault while maintaining flexibility for other environments where vault storage may not be necessary.</p>



<h2 class="wp-block-heading">Build Manager &#8211; Selecting you PAM</h2>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-4 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="451" height="402" data-id="7309" src="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.35.07-1.png" alt="" class="wp-image-7309" srcset="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.35.07-1.png 451w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.35.07-1-300x267.png 300w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.35.07-1-50x45.png 50w" sizes="auto, (max-width: 451px) 100vw, 451px" /></figure>
</figure>



<p>This dialog box is part of the <strong>GLU.Engine Build Manager</strong> interface, allowing users to configure the environment and key settings for their GLU.Engine startup process. The key feature is the ability to specify which <strong>Vault</strong> provider (either <strong>Azure Key Vault</strong> or <strong>AWS Secrets Manager</strong>) will manage your secret credentials at runtime.</p>



<p>GLU.Engine requires secret credentials (such as database passwords, API keys, etc.) to authenticate services and API connections during startup. These credentials are securely stored in either <strong>Azure Key Vault</strong> or <strong>AWS Secrets Manager</strong>, depending on your selection. Proper API connections between GLU.Engine and the selected vault provider are essential to ensure that the secrets are retrieved successfully when the engine is launched. (For more information about how the API connection is made during start up of the GLU.Engine please contact GLU Support.)</p>



<h3 class="wp-block-heading">Key VAULT Components of the Dialog Box:</h3>



<p><strong>Select Vault</strong>:</p>



<ol class="wp-block-list">
<li></li>
</ol>



<ul class="wp-block-list">
<li>This dropdown allows you to choose where the GLU.Engine will retrieve its secret credentials at startup.</li>



<li><strong>Vault Azure</strong>: This option selects <strong>Azure Key Vault</strong> as the credential storage provider.
<ul class="wp-block-list">
<li><strong>Azure Key Vault</strong> is Microsoft&#8217;s cloud-based service for securely storing and accessing sensitive information like API keys, passwords, and certificates.</li>
</ul>
</li>



<li><strong>Vault AWS</strong>: This option selects <strong>AWS Secrets Manager</strong> as the credential storage provider.<ul><li><strong>AWS Secrets Manager</strong> is Amazon Web Services’ solution for storing and managing secrets securely in the cloud.</li></ul></li>
</ul>



<h3 class="wp-block-heading">Important Considerations:</h3>



<ul class="wp-block-list">
<li>Ensure the API connection to <strong>Azure Key Vault</strong> or <strong>AWS Secrets Manager</strong> is properly configured before starting the engine. Without this connection, the GLU.Engine will not be able to pull the required credentials, and the startup process will fail.</li>
</ul>



<h2 class="wp-block-heading">Build Manager &#8211; Getting the <em><strong>Secret-name</strong></em> for the VAULT</h2>



<p>In the download screen accessible from the build manager it is possible to see a column with an indication that the build has been completed with VAULTs in place. </p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-5 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="482" data-id="7317" src="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.35.55-1-1024x482.png" alt="" class="wp-image-7317" srcset="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.35.55-1-1024x482.png 1024w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.35.55-1-300x141.png 300w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.35.55-1-768x361.png 768w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.35.55-1-50x24.png 50w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.35.55-1.png 1031w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</figure>



<p>If the icon is selected then the Vault Keys dialogue will display this will show the <em><strong>Secret-name</strong></em> which should be used to store the secret against in the PAM environment.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-6 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="487" data-id="7316" src="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.36.09-1024x487.png" alt="" class="wp-image-7316" srcset="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.36.09-1024x487.png 1024w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.36.09-300x143.png 300w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.36.09-768x365.png 768w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.36.09-50x24.png 50w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-18-at-15.36.09.png 1031w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</figure>



<p>An example of how this is configured in Azure Devops is provided below showing the <em><strong>Secret-name</strong></em> for the secret <em>pinToALLTheMoney</em>.</p>



<figure class="wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-7 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="553" data-id="7320" src="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-19-at-08.54.47-1024x553.png" alt="" class="wp-image-7320" srcset="https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-19-at-08.54.47-1024x553.png 1024w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-19-at-08.54.47-300x162.png 300w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-19-at-08.54.47-768x415.png 768w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-19-at-08.54.47-50x27.png 50w, https://glu.global/wp-content/uploads/2024/09/Screenshot-2024-09-19-at-08.54.47.png 1201w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
</figure>



<h2 class="wp-block-heading"><strong>Benefits of Using Vault</strong></h2>



<p>• <strong>Security</strong>: Credentials are stored in a centralized, secure location and are not exposed in configuration files or UI.</p>



<p>• <strong>Manageability</strong>: Changes to credentials require updating the secrets in the VAULT only, without needing to redistribute configuration files.</p>



<p>• <strong>Compliance</strong>: Using Vault aids in compliance with regulations that require rigorous data security measures, such as GDPR, POPIA &amp; NCPF.</p>



<h3 class="wp-block-heading"><strong>Important Notes</strong></h3>



<p>• Ensure that the VAULT is properly configured at GLU.Engine runtime.</p>



<p>• Verify that all secrets (username, password) are correctly set up in the VAULT before enabling the Vault flags.</p>



<h2 class="wp-block-heading"><strong>FAQs</strong></h2>



<p>Here are the questions followed by the responses for each:</p>



<h3 class="wp-block-heading"><strong>Question 1:</strong></h3>



<p><strong>What happens if the Secret-Name in the PAM does not exist or is misconfigured in GLU.Engine?</strong></p>



<p><strong>Response</strong>:<br>If the Secret-Name in the PAM (Azure Key Vault or AWS Secrets Manager) does not exist or is misconfigured, GLU.Engine will fallback to using the existing secret stored in GLU.Ware. This behavior could occur if the vault retrieval fails, which could lead to the engine using outdated or less secure credentials.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading"><strong>Question 2:</strong></h3>



<p><strong>What occurs when the APIs connecting GLU.Engine to the PAM are misconfigured?</strong></p>



<p><strong>Response</strong>:<br>If the APIs to connect GLU.Engine to the PAM are misconfigured, the GLU.Engine will not start. This is because the necessary secrets for authentication or service configuration will not be retrieved from the vault, causing the startup process to fail.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading"><strong>Question 3:</strong></h3>



<p><strong>How does the Vault Keys dialogue display Secret-names for global variables in GLU.Engine?</strong></p>



<p><strong>Response</strong>:<br>The Vault Keys dialogue displays all the Secret-names for all global variables that GLU.Engine can access, where the <strong>VAULT</strong> tickbox is checked. This helps users view which secrets are managed in the vaults (Azure Key Vault or AWS Secrets Manager) and ensures they are correctly stored and retrieved.</p>



<p></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Comprehensive Data Security</title>
		<link>https://glu.global/glu-guide/masking-sensitive-data-parameters-in-logs-2/</link>
		
		<dc:creator><![CDATA[Richard Price]]></dc:creator>
		<pubDate>Tue, 31 Jan 2023 08:57:11 +0000</pubDate>
				<guid isPermaLink="false">https://glu.global/?post_type=ht_kb&#038;p=4072</guid>

					<description><![CDATA[GLU.Engine have robust data security measures, encompassing both data masking and encryption to protect sensitive information across all system interactions—including logging, JMX API calls, and internal JVM processes. • Data Masking: This technique involves obscuring sensitive data within outputs to ensure that the data cannot be reconstructed or retrieved in its original form. Masking is [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>GLU.Engine have robust data security measures, encompassing both data masking and encryption to protect sensitive information across all system interactions—including logging, JMX API calls, and internal JVM processes.</p>



<p>• <strong>Data Masking</strong>: This technique involves obscuring sensitive data within outputs to ensure that the data cannot be reconstructed or retrieved in its original form. Masking is applied to logs and JMX API responses to prevent sensitive information from being exposed. For instance, a masked credit card number might appear as ************* in logs.</p>



<p>• <strong>Data Encryption</strong>: In addition to masking, the GLU.Engine employs encryption to protect data at rest and in transit. Encryption involves converting data into a coded format that can only be read or processed after being decrypted with a key. This ensures that even if data is intercepted, it remains unreadable without the corresponding decryption key.</p>



<p>• <strong>JMX API Data Protection</strong>: Enhanced security measures are also applied to data accessed through JMX API calls. This includes both masking and encrypting data to ensure robust security against unauthorized access.</p>



<p>• <strong>Comprehensive JVM Data Security</strong>: The security measures extend throughout the JVM, safeguarding data involved in various processes and stored in memory spaces within the GLU.Engine. This integrated approach ensures that all sensitive data handled by the system is thoroughly protected.</p>



<p>• <strong>Flexible Tagging for Data Protection</strong>: Administrators can define specific security rules for data handling and protection in the ‘Mask PAYLOAD Values in Logs’ section of the Transaction Manager Panel. This allows for targeted application of masking and encryption rules across different data types and system interactions.</p>



<p>This strategic implementation of data masking and encryption within the GLU.Engine not only shields sensitive data from unauthorized access but also ensures the integrity and confidentiality of data across the platform’s operational framework.</p>



<p>In situations where the parameters in the messages may contain sensitive information that could pose a security risk if displayed in the logs, the GLU.Engine generates two types of logs that require controlled value representation:</p>



<p></p>



<p></p>



<ol class="wp-block-list">
<li> logs that include parameters in the<strong> &#8216;PAYLOAD&#8217;</strong> and</li>



<li>logs that print parameters as <strong>&#8216;PARAM&#8217;</strong>.</li>
</ol>



<p>The masking of sensitive data in log entries can be controlled by configuring the PAYLOAD and PARAM log masking.</p>



<p></p>



<p></p>



<p></p>



<p>The PAYLOAD log masking is managed at the transaction level, while the PARAM log masking is managed at the parameter configuration level. It is important to note that while the PAYLOAD log masks only parameters in the PAYLOAD when printed in the log, the mask does not affect the unmarshalled value.</p>



<p></p>



<p></p>



<p></p>



<p>To mask the unmarshalled value, a mask for the full string as it appears in the logs must be added.</p>



<p></p>



<p></p>



<p></p>



<p>Then the PARAM log will be masked in the values when un-marshalled.</p>



<p></p>



<p></p>



<p></p>



<p>To mask PAYLOAD values, the <strong>&#8216;<em>Mask PAYLOAD Values in Logs</em>&#8216;</strong> field in the Transaction Manager Panel can be used to define the &#8216;<em>tags</em>&#8216; for any values that need to be masked, along with the GLU reserved word &#8220;GLU_MASK&#8221; (e.g. &#8220;username&#8221;:&#8221;GLU_MASK&#8221;).</p>



<p></p>



<p></p>



<p></p>



<p>This will replace the value for &#8220;username&#8221; with &#8220;**********&#8221;.</p>



<p></p>



<p></p>



<p></p>



<p>Since tags are used, any payload value can be masked, not just the parameter values within the payload.</p>



<p></p>



<p></p>



<p></p>



<p>The tags to be masked can be copied from the payload template configuration and will vary depending on the payload type (e.g. XML, JSON, SQL call, etc.).</p>



<p></p>



<p></p>



<p></p>



<p><strong>NOTE</strong>: the GLU_MASK value used is the full line, so if you complete the line entry with &#8220;username&#8221;: <strong>&#8220;GLU_MASK&#8221;,</strong> the value will also be included in the masking of username &#8211; e.g. &#8220;**********&#8221;.</p>



<p></p>



<p></p>



<p></p>


<div class="wp-block-image">
<figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="319" src="https://glu.global/wp-content/uploads/2024/05/Screenshot-2024-05-06-at-09.06.08-1-1024x319.png" alt="" class="wp-image-7099" style="width:625px;height:auto" srcset="https://glu.global/wp-content/uploads/2024/05/Screenshot-2024-05-06-at-09.06.08-1-1024x319.png 1024w, https://glu.global/wp-content/uploads/2024/05/Screenshot-2024-05-06-at-09.06.08-1-300x94.png 300w, https://glu.global/wp-content/uploads/2024/05/Screenshot-2024-05-06-at-09.06.08-1-768x240.png 768w, https://glu.global/wp-content/uploads/2024/05/Screenshot-2024-05-06-at-09.06.08-1-50x16.png 50w, https://glu.global/wp-content/uploads/2024/05/Screenshot-2024-05-06-at-09.06.08-1.png 1212w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure></div>


<p><br>To mask PARAM values, the <strong>&#8220;<em>Mask PARAM Value in Logs</em>&#8220;</strong> checkbox (which by default is <strong>&#8216;checked&#8217;</strong>) must be unchecked.</p>



<p></p>



<p></p>



<p></p>



<p>Any payload tag (PAYLOAD logs) or parameter name (PARAM logs) that is configured to be masked will be masked in in all logs (INFO, WARN, DEBUG etc.) for all logs associated with a particular transaction.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
