QuestionQ22

Implementing observability practices and troubleshooting issues

You are running an application on Compute Engine and collecting its logs through Stackdriver. You discover that some personally identifiable information (PII) is leaking into certain log entry fields. You want to prevent these fields from being written into new log entries as quickly as possible.

What should you do?

Explanation

The Stackdriver/Cloud Logging agent on Compute Engine is a Fluentd-based agent. You can edit its local configuration to insert the built-in filter_record_transformer filter plugin, which can remove or transform specific fields (using its remove_keys parameter) from log records as they flow through the agent, before they are ever sent to Cloud Logging. This is the fastest remediation because it only requires updating the Fluentd agent configuration on the instance and restarting the agent — it does not require an application code change, and it avoids the extra latency and engineering effort of an intermediate storage-and-processing pipeline.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!