Skip to main content
drupalreleases
Release: Cms 2.2.3 — Update released for Drupal core (2.2.3)! Release: Easy Breadcrumb 2.0.11 — Minor update available for module easy_breadcrumb (2.0.11). Release: Bootstrap 8.x-3.42 — Minor update available for theme bootstrap (8.x-3.42). Release: Editoria11y Accessibility Checker 3.0.10 — Minor update available for module editoria11y (3.0.10). Release: Editoria11y Accessibility Checker 2.2.24 — Minor update available for module editoria11y (2.2.24). Release: Leaflet 10.4.13 — Minor update available for module leaflet (10.4.13). Release: Flag 5.1.1 — Minor update available for module flag (5.1.1). Release: Layout Paragraphs 3.0.0-beta5 — New beta version released for module layout_paragraphs (3.0.0-beta5). Module Revived: Bootstrap 8.x-3.41 — Theme bootstrap updated after 6 months of inactivity (8.x-3.41). Security Coverage: Component Library — Module component_library now has official Drupal security advisory coverage.

Log Masker

No security coverage

Part of the LOG ecosystem · 9 projects

View on drupal.org

Log Masker masks personal data in every Drupal log entry before it reaches a logger, without changing the calling code. Its goal is to mask as much personal data as possible: each kind of data is handled by a masking rule. Version 1 ships the rule for email addresses ([email protected] is logged as j***.***@e***.***); rules for IP addresses and phone numbers are planned, and sites can add their own rules.

Features

  • Works with every logger (dblog, syslog, contrib loggers) and every channel, including \Drupal::logger().
  • Masks the message, the placeholders, nested context values, request_uri and referer.
  • Detects URL-encoded addresses (jean.dupont%40example.com), addresses in JSON payloads and exception messages (e.g. Guzzle), and addresses truncated at the end of a value.
  • Exceptions in the log context are replaced by a neutral, masked exception.
  • Fail-closed by default: if masking fails, the message is withheld instead of being written unmasked.
  • The logger.* services keep their own class: no decoration, no replacement of the logger factory.
  • Extensible: add your own rules as services tagged log_masker.rule.

This is pseudonymisation, not anonymisation (GDPR recital 26). Masked logs remain personal data; not logging the data remains the best protection.

Post-Installation

Masking is active as soon as the module is installed. Settings are under Configuration > Development > Log Masker (permission Administer Log Masker): mask character and length, revealed characters, failure mode and excluded channels. A preview shows the result on fictitious addresses. Disabling masking requires an explicit confirmation, every change is audited, and the status report warns about any weakened setting and about loggers that escape masking.

Additional Requirements

Drupal core 10.5, 11 or 12 and PHP 8.3 or later. No other dependency.

None. Note: with the Monolog module enabled, version 1 cannot mask (the status report shows an error). Monolog support is planned for 2.x.

Similar projects

  • Log Middleware: a generic hook to alter log entries. It replaces the logger factory and runs before the channel adds request_uri and referer; it does not mask data by itself.
  • Privacy Log: also privacy-oriented logging.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
2
Tracked since
Oct 2026
Latest release
2 hours ago
Releases (12 mo)
2 ▲ from 0
Maintenance
Active

Releases

Version Type Core Release date
1.0.0-alpha2 Pre-release 10–11 Oct 7, 2026
1.0.0-alpha1 Pre-release 10–11 Oct 7, 2026