Log Masker masks personal data in every Drupal log entry before it reaches a logger, without changing the calling code. Its goal is to mask as much personal data as possible: each kind of data is handled by a masking rule. Version 1 ships the rule for email addresses ([email protected] is logged as j***.***@e***.***); rules for IP addresses and phone numbers are planned, and sites can add their own rules.
Features
- Works with every logger (dblog, syslog, contrib loggers) and every channel, including
\Drupal::logger(). - Masks the message, the placeholders, nested context values,
request_uriandreferer. - Detects URL-encoded addresses (
jean.dupont%40example.com), addresses in JSON payloads and exception messages (e.g. Guzzle), and addresses truncated at the end of a value. - Exceptions in the log context are replaced by a neutral, masked exception.
- Fail-closed by default: if masking fails, the message is withheld instead of being written unmasked.
- The
logger.*services keep their own class: no decoration, no replacement of the logger factory. - Extensible: add your own rules as services tagged
log_masker.rule.
This is pseudonymisation, not anonymisation (GDPR recital 26). Masked logs remain personal data; not logging the data remains the best protection.
Post-Installation
Masking is active as soon as the module is installed. Settings are under Configuration > Development > Log Masker (permission Administer Log Masker): mask character and length, revealed characters, failure mode and excluded channels. A preview shows the result on fictitious addresses. Disabling masking requires an explicit confirmation, every change is audited, and the status report warns about any weakened setting and about loggers that escape masking.
Additional Requirements
Drupal core 10.5, 11 or 12 and PHP 8.3 or later. No other dependency.
Recommended modules/libraries
None. Note: with the Monolog module enabled, version 1 cannot mask (the status report shows an error). Monolog support is planned for 2.x.
Similar projects
- Log Middleware: a generic hook to alter log entries. It replaces the logger factory and runs before the channel adds
request_uriandreferer; it does not mask data by itself. - Privacy Log: also privacy-oriented logging.
Depends on
Dependencies of the latest stable release
No dependencies recorded for this project.
Required by
Tracked projects that depend on this one
No tracked projects depend on this one yet.
More in the LOG ecosystem
Most installed first
Activity
Releases
| Version | Type | Core | Release date | |
|---|---|---|---|---|
| 1.0.0-alpha2 | Pre-release | 10–11 | Oct 7, 2026 | |
| 1.0.0-alpha1 | Pre-release | 10–11 | Oct 7, 2026 |