Lesson 18 / 25

Enrichment, Filtering and Redaction

Clean data before export.

Processors for quality and privacy

Useful processors include k8sattributes (adds pod, namespace and deployment names), resourcedetection (cloud and host metadata), attributes and transform (rename, hash or delete attributes using OTTL, the OpenTelemetry Transformation Language), filter (drop health-check spans or noisy metrics) and redaction (remove values matching sensitive patterns). Doing this centrally ensures personal data and secrets never reach third-party backends.

Dropping health checks and removing sensitive attributes

Filter and attributes processors (contrib distribution).

processors:
  filter/health:
    error_mode: ignore
    traces:
      span:
        - 'attributes["url.path"] == "/healthz"'
  attributes/scrub:
    actions:
      - key: user.email
        action: delete
      - key: enduser.id
        action: hash

service:
  pipelines:
    traces:
      receivers: [otlp]
      processors: [memory_limiter, filter/health, attributes/scrub, batch]
      exporters: [otlp/tempo]

Do not rely on redaction alone

Avoid recording sensitive data in the first place; Collector redaction is a safety net.

Quick check: Which processor adds Kubernetes pod and namespace names to telemetry?

  • k8sattributes
  • batch
  • debug
  • memory_limiter
Answer

k8sattributes — Enrichment from the Kubernetes API.