Hosting security

What should I redact from diagnostic logs?

Short answer

Remove credentials, session identifiers, tokens, API keys, private keys and personal data before sharing logs. Share only the time window and entries needed to investigate the problem.

What changes the answer

  • Authorization headers and cookies
  • Query strings that contain tokens
  • Personal data such as email addresses

Treat sharing as publishing

A log pasted into a support ticket, forum or chat may be visible to many people and stored for a long time. Assume that anything you paste cannot be taken back, and clean it first.

What to remove

  • Passwords, API keys, bearer tokens, session cookies and private keys.
  • Authorization and cookie headers, if request headers were logged.
  • Full environment files and configuration files that hold secrets.
  • URLs with tokens in the query string. The HTTP specification has a section on the disclosure of sensitive information in URIs, because URLs end up in logs, history and referrer data.
  • Personal data you do not need for the investigation, such as email addresses, names and payment details. Replace them with placeholders.

The OWASP Logging Cheat Sheet also advises against recording sensitive data in logs in the first place, so fix the source if your application logs secrets.

What to keep

Keep what makes the problem diagnosable: timestamps, status codes, error messages, request paths without secrets, and the service name. Replace removed values with a clear marker, for example [REDACTED], so the structure stays readable.

A practical routine

  1. Cut the log to the smallest useful time window around the failure.
  2. Search for words such as password, token, secret, authorization and cookie.
  3. Read through the result once more as a stranger would.

If you shared a secret by mistake

Rotate it immediately. Revoke the API key or token, change the password and end the sessions. Deleting the post is not enough, as copies may already exist.

Share through the right channel

Send logs through the channel your provider recommends, such as a support ticket, rather than a public forum, and say which parts you removed. If someone needs more detail, you can provide it privately after confirming who is asking and why. Keep an unredacted copy only where you store other sensitive operational data, and delete it when the issue is closed.