Jump to content

how to get anonymized log file?


Go to solution Solved by GrimReaper,

Recommended Posts

Posted (edited)

If I go to the admin Logs page and use either open or download, the log is not anonymized.  I still see the Windows username and IP's.  How do I get the anonymized version?

Edited by justinrh
GrimReaper
Posted

Remote or local IPs? 

Posted

local

GrimReaper
Posted (edited)

Those are not anonymized (and why would they be, besides making troubleshooting an order of magnitude harder)?

Edited by GrimReaper
Posted

So what all does get anonymized?  I didn't see anything in the Logs KB article.

  • Solution
GrimReaper
Posted (edited)

AFAIK remote IPs, remote domains, apikeys... anything that would provide malicious individuals outside your network information to access your network/identify/access your server/users externally.

Edited by GrimReaper
  • Thanks 1
Posted
1 hour ago, GrimReaper said:

AFAIK remote IPs, remote domains, apikeys... anything that would provide malicious individuals outside your network information to access your network/identify/access your server/users externally.

Where can you enable this?

Happy2Play
Posted
Just now, MSI2017 said:

Where can you enable this?

click on a log via Logs.

  • Like 1
seanbuff
Posted
1 minute ago, MSI2017 said:

Where can you enable this?

You get the option once you select a server log in the web UI

image.png.c0048ed9dfb4b454b110f73d14cb2237.png

  • Like 1
  • Thanks 1
Posted
1 minute ago, seanbuff said:

You get the option once you select a server log in the web UI

image.png.c0048ed9dfb4b454b110f73d14cb2237.png

Than it's broken. I have it enabled yet my domain is still there

Happy2Play
Posted
5 minutes ago, MSI2017 said:

Than it's broken. I have it enabled yet my domain is still there

You shall have to elaborate but yes there are some areas that still show your info (Host= and Forwarder info) but the majority are replaced with hostx 

  • Agree 1
Posted
12 minutes ago, seanbuff said:

You get the option once you select a server log in the web UI

So the logs are anonymized ONLY IF you click the log file (where the option is shown)?

I'd hope it would be anonymized by default, then if you don't want it cleansed you can click the lock and toggle off the option.

Happy2Play
Posted
Just now, justinrh said:

So the logs are anonymized ONLY IF you click the log file (where the option is shown)?

I'd hope it would be anonymized by default, then if you don't want it cleansed you can click the lock and toggle off the option.

Pretty sure they are when you download them as I don't remember enabling it but can test on a new install if needed.

But download from Logs or clicking on the log provides an anonymized log assuming it is enabled.

Posted
11 hours ago, Happy2Play said:

You shall have to elaborate but yes there are some areas that still show your info (Host= and Forwarder info) but the majority are replaced with hostx 

The domain used to connect to my emby is still there

  • Agree 1
GrimReaper
Posted (edited)
4 hours ago, MSI2017 said:

The domain used to connect to my emby is still there

Yes, see it also:

2023-01-15 15:47:38.503 Info Server: http/2 POST https://emby_remote_ip:8920/emby/Users/authenticatebyname?X-Emby-Client=Emby Web&X-Emby-Device-Name=Microsoft Edge Windows&X-Emby-Device-Id=fff157c9-c4ae-4701-ac99-a7b4cb717816&X-Emby-Client-Version=4.7.10.0. Accept=application/json, Host=NOT ANONYMIZED:8920, User-Agent=Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 Edg/110.0.0.0, :method=POST, Accept-Encoding=gzip, deflate, br, Accept-Language=en-US,en;q=0.9,hr;q=0.8, Content-Type=application/x-www-form-urlencoded; charset=UTF-8, Origin=https://NOT ANONYMIZED:8920, Referer=https://NOT ANONYMIZED:8920/web/index.html, Content-Length=32, sec-ch-ua="Chromium";v="110", "Not A(Brand";v="24", "Microsoft Edge";v="110", sec-ch-ua-mobile=?0, sec-ch-ua-platform="Windows", sec-fetch-site=same-origin, sec-fetch-mode=cors, sec-fetch-dest=empty

Though the entry starts correctly, Host, Origin and Referer are not anonymized down the line. @Luke

Edited by GrimReaper
Typo
  • Thanks 2
Posted
3 hours ago, GrimReaper said:

Yes, see it also:

2023-01-15 15:47:38.503 Info Server: http/2 POST https://emby_remote_ip:8920/emby/Users/authenticatebyname?X-Emby-Client=Emby Web&X-Emby-Device-Name=Microsoft Edge Windows&X-Emby-Device-Id=fff157c9-c4ae-4701-ac99-a7b4cb717816&X-Emby-Client-Version=4.7.10.0. Accept=application/json, Host=NOT ANONYMIZED:8920, User-Agent=Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 Edg/110.0.0.0, :method=POST, Accept-Encoding=gzip, deflate, br, Accept-Language=en-US,en;q=0.9,hr;q=0.8, Content-Type=application/x-www-form-urlencoded; charset=UTF-8, Origin=https://NOT ANONYMIZED:8920, Referer=https://NOT ANONYMIZED:8920/web/index.html, Content-Length=32, sec-ch-ua="Chromium";v="110", "Not A(Brand";v="24", "Microsoft Edge";v="110", sec-ch-ua-mobile=?0, sec-ch-ua-platform="Windows", sec-fetch-site=same-origin, sec-fetch-mode=cors, sec-fetch-dest=empty

Though the entry starts correctly, Host, Origin and Referer are not anonymized down the line. @Luke

Good to know its not just me

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...