Mask Sensitive Data on a Target Database

You can run a Data Masking job from the Data Masking page or the Masking Policy Details page. You can run only one data masking job at a time on a target database.

Mask Sensitive Data from the Data Masking Page

Be sure that you are not trying to mask sensitive data on your production database.

  1. Under Data Safe - Database Security, select Data masking.

  2. Select Mask sensitive data.

    The Mask sensitive data window is displayed.

  3. Select a target database. If needed, select a different compartment.

  4. Select a masking policy for the selected target database. If needed, select a different compartment.

  5. (Optional) Select the tablespace.

  6. (Optional) Enter a specific seed value to be used for user defined functions.

    Using the same seed value across user defined functions ensures consistency in masked values. Note what seed value you use if you'd like to use the same value elsewhere.

  7. If needed, under Target credentials, enter a Username and Password.

    User credentials are required when masking policies use pre-masking scripts, post-masking scripts, SQL expressions, user-defined functions (UDFs), or post-processing functions. For all other masking policies, credentials remain optional. Credentials are used only during pre-masking checks and masking job execution.

  8. Select Mask Data.

    Review the warning message about not masking data on a production database.

  9. If your masking policy contains any deterministic encryption or deterministic substitution formats, then you will be prompted to enter a seed value. Take note of the seed value you entered to both ensure consistency across masking policies and to later provide the same seed value for decryption if desired.

  10. On the work request page, monitor the progress of the masking job.

    Work request logs include the name of the table currently being processed. This information enables you to monitor the progress of a masking job and identify which tables have been successfully masked. If a masking job fails, you can review the work request logs to determine the last table processed and identify which tables were masked before the failure occurred. This information can assist with troubleshooting and validating masking job progress.

Mask Sensitive Data from the Masking Policies Details Page

  1. Under Data Safe - Database Security, select Data masking.

  2. Under Data masking, select Masking policies.

  3. Select the name of a masking policy to view its details.

    The Masking Policies Details page is displayed.

  4. Select Mask data.

    The Mask Sensitive Data page is displayed.

  5. Select the target database that you want to mask. If needed select a different compartment.

  6. (Optional) Enter a specific seed value to be used for user defined functions.

    Using the same seed value across user defined functions ensures consistency in masked values. Note what seed value you use if you'd like to use the same value elsewhere.

  7. If needed, under Target credentials, enter a Username and Password.

    User credentials are required when masking policies use pre-masking scripts, post-masking scripts, SQL expressions, user-defined functions (UDFs), or post-processing functions. For all other masking policies, credentials remain optional. Credentials are used only during pre-masking checks and masking job execution.

  8. Select Mask Data.

    Review the warning message about not masking data on a production database.

  9. If your masking policy contains any deterministic encryption or deterministic substitution formats, then you will be prompted to enter a seed value. Take note of the seed value you entered to both ensure consistency across masking policies and to later provide the same seed value for decryption if desired.

  10. On the work request page, monitor the progress of the masking job.

    Work request logs include the name of the table currently being processed. This information enables you to monitor the progress of a masking job and identify which tables have been successfully masked. If a masking job fails, you can review the work request logs to determine the last table processed and identify which tables were masked before the failure occurred. This information can assist with troubleshooting and validating masking job progress.

Rerun a Failed Masking Job

If a masking job has failed, you can rerun the masking job from the failed step, pre masking script, or post masking script. The masking job will start from the step you select and continue through the rest of the masking job.

  1. Under Data Safe - Database Security, select Data masking.

  2. Under Data masking, select Masking policies.

  3. Select the masking policy for the failed masking job.

  4. Select the Work request tab.

  5. Review the work request logs to determine the last table processed and identify which tables were masked before the failure occurred.

  6. Select a specific work request from the list to view details.

  7. From the Actions menu, select Rerun.

  8. Select which step you would like the masking job to rerun from.

    The masking job will start from the step you select and continue through the rest of the masking job.

  9. If you specified credentials for the failed data masking job, under Target Credentials, enter the username and password for the Data Masking account on your target database.

    Credentials for the Data Masking account are required when masking policies use pre-masking scripts, post-masking scripts, SQL expressions, user-defined functions (UDFs), or post-processing functions. For all other masking policies, credentials remain optional. Credentials are used only during pre-masking checks and masking job execution.

  10. Click Rerun.