Skip to content

Redact secrets from a log before you share it

← Log Viewer
By Underrated SoftwareUpdated

Logs are unusually easy to overshare. A troubleshooting excerpt can carry bearer tokens, API keys, session IDs, email addresses, customer IP addresses, or internal hostnames beside the error you meant to send. Treat a log like any other production data: remove secrets and personal data before pasting it into a ticket, chat, issue, or third-party service.

Turn on local redaction

In Log Viewer, open Settings > Redaction and turn on Redact copied and exported logs. The shipped rules recognize conservative token patterns, email addresses, and valid IPv4 addresses. You can edit their names, regular expressions, and replacements, add rules for your own identifiers, or restore the defaults.

Redaction is local and outbound only. The open log stays readable, the original file is never changed, and Find and Filter still operate on the original text. A regular Copy or filtered Export applies the enabled rules, giving repeated values stable labels such as IP-1 and EMAIL-1 within that one operation.

Hover a marked value to see that the local redaction setting will protect copied and exported text.
Hover a marked value to see that the local redaction setting will protect copied and exported text.

Export the whole log as a redacted copy

To make a shareable copy of every line, turn on Filter, choose the regular-expression mode, and enter .* as the filter. It matches every line, so Export writes the complete view. With Redaction enabled, the exported file masks every enabled match while preserving the source encoding and line endings. Save it under a new name and share that copy, not the original.

For a smaller incident excerpt, filter for the failing request, error, or time range instead. Export includes only the matching lines and any context you chose, and redaction is applied to both. Review the resulting copy before sending it: no general-purpose pattern can know which value is sensitive in your system.

Make rules fit your system

Start narrowly. A rule that matches too broadly can erase useful diagnostics; a rule that matches too little can leave a secret behind. Add recognizable prefixes for your tokens, such as a product-specific API-key prefix, and test with a copied excerpt. Rule order matters when patterns overlap: the earlier rule wins.

Redaction is a safety aid, not a reason to paste production data carelessly. If a value is especially sensitive, remove the line or replace it manually as well. Never rely on a visual marker alone: share the redacted Copy or exported file.

FAQ

Does redaction change my original log file?

No. It applies only to regular Copy and filtered Export while the setting is on. The file on disk and the readable log window stay unchanged.

How do I export every line with redaction applied?

Turn on Filter, select regular-expression mode, enter .*, then use Export. That filter matches every line; the exported copy applies every enabled redaction rule.

Can I redact identifiers other than tokens, emails, and IP addresses?

Yes. Add or edit an ordered rule in Settings > Redaction. Use a narrow regular expression for your application-specific identifier and a replacement such as CUSTOMER-{n}.

Try Log Viewer

See what Log Viewer does and check whether it fits your task.

FreemacOSDownload on the Mac App Store (opens in a new tab)