LinkMesh

Search docs, blog and changelog

ENDE

OpenTelemetry PII filtering

Stop sensitive telemetry before it reaches the cloud

PII that reaches your backend gets indexed, retained, and queryable — and scrubbing it out later is expensive and never complete. LinkMesh manages masking, redaction, and drop rules that run in your own OpenTelemetry Collectors, on the host, before anything is sent. Self-hosted, so sensitive values never leave your network — and priced per collector, not per gigabyte.

Start free →

25 Collectors free after a no-card registration · 5 without one How the free tier works

Once PII is in the index, it’s already too late

The only reliable place to remove sensitive data is before it leaves the host. Every step after that — the network, the backend, the replicas, the exports — is a place the raw value has already been. These are the reasons after-the-fact scrubbing keeps failing.

PII gets indexed and retained

An email, a card number, or a user ID slips into a log line and lands in your backend, where it is indexed, retained, and queryable long after it should have been gone.

Scrubbing after the fact is expensive

Once sensitive data is in the index, removing it means re-processing, re-indexing, or deleting whole slices of history — costly, slow, and never quite complete.

Compliance exposure travels with the data

Every backend, replica, and downstream export that received the raw record is now in scope for GDPR, HIPAA, or PCI — and each one is a place an auditor will look.

Developers can’t predict every field

A new service logs a request body, a library adds a header, a stack trace embeds a token. PII arrives through paths nobody reviewed, in fields nobody expected.

Backend-side redaction is too late

By the time a masking rule runs inside the backend, the raw value has already crossed your network boundary and been written down at least once.

No safe way to change a rule

Nobody edits a masking regex in production on faith. Without a way to see what a rule matches first, the sensitive fields keep flowing untouched.

Masking happens on the host, before egress

Sources feed your collectors; on the collector, telemetry is masked, redacted, or dropped; only the cleaned records go to your backends. LinkMesh manages the masking processors and reads health — it never sits in the data path, so raw values never transit it.

CONTROL PLANE · config, health (never telemetry)LinkMesh — self-hosted control planemanages the mask / redact / drop processors on every collectorconfig · healthSourceshosts · K8sapps · syslogCollector Fleetmask · redact · hash · dropotelcol-contrib · Grafana Alloymanaged by LinkMeshYour Backendsonly cleaned recordsLoki · Splunk · Elasticany OTLPrawmasked
Masking runs on the collector; only cleaned records reach your backends. LinkMesh manages the processors and stays out of the data path.

01

Built-in masking templates

Problem

The common cases — credit card numbers, email addresses, phone numbers — recur in every pipeline, and hand-writing a correct regex for each, on every collector, is how they get missed.

LinkMesh

LinkMesh ships built-in masking templates for the patterns that show up everywhere: credit cards, emails, phone numbers, and similar well-known formats. Attach one to a collector or a whole group and it renders to OTTL and runs in the collector, on the host, before anything is sent.

The obvious PII is covered by a reviewed template, not a regex each team reinvents.

How-to: mask PII before egress →
The LinkMesh processor library, showing built-in masking, filtering, and sampling templates that attach to a collector or a collector group.
Built-in masking templates in the processor library — attach one to a collector or a whole group.

02

Custom OTTL rules for your fields

Problem

Your sensitive fields are not the textbook ones. Account IDs, internal tokens, secrets, and user identifiers are shaped like your systems, and no generic pattern catches them.

LinkMesh

Write custom rules in OTTL — the OpenTelemetry Transformation Language — targeting exactly your attributes and body fields: account IDs, API tokens, secrets, user identifiers. LinkMesh renders them into the collector’s processing chain alongside the built-in templates.

Redaction that matches your data model, not just the patterns everyone already knows.

How processors transform telemetry →

03

Drop, redact, or hash — per field

Problem

Not every sensitive field wants the same treatment. Some must vanish entirely, some need to stay readable-but-masked, and some have to remain correlatable without exposing the value.

LinkMesh

Choose the pattern per rule: drop the record or attribute outright, redact the value to a fixed placeholder, or hash it so the same input stays consistent across records without ever revealing the original. Mix all three in one collector’s chain.

The right disposal for each field — gone, masked, or hashed — instead of one blunt setting.

How-to: filter records on a route →

04

Masking as fleet-wide group policy

Problem

A masking rule that lives on one collector protects one collector. A new host, a new team’s pipeline, or a forgotten node ships raw PII straight past every convention you agreed on.

LinkMesh

Attach masking processors at the group level and every collector in the group inherits them, independent of its local pipeline. New collectors pick up the group’s masking policy the moment they enroll — the guardrail applies before anyone configures anything.

Masking becomes policy the whole fleet inherits, not a rule someone remembers to add.

How collector groups carry policy →

05

Preview a rule against real records

Problem

Nobody should point a redaction rule at production without seeing what it does. A rule that is too narrow leaks; a rule that is too broad destroys the field you needed.

LinkMesh

LinkMesh previews each processor against real captured records: the input on one side, the rule and generated OTTL in the middle, the masked output on the other. You see exactly which fields a rule touches — and which it misses — before it reaches a single collector.

Ship a masking rule knowing precisely what it redacts, because you watched it run.

How processor preview works →
The LinkMesh processor preview — a sample record entering a rule on the left, the rule and generated OTTL in the middle, and the transformed output on the right.
Preview a masking rule against a real record — input, rule, and output side by side — before you ship it.

06

Self-hosted — values never leave your network

Problem

A masking service you send data to is a masking service that has already seen the raw PII. The moment sensitive values cross to a third party, the exposure exists whether or not it is masked afterward.

LinkMesh

LinkMesh is a self-hosted control plane and never sits in the data path. Masking runs inside your own collectors, on your own hosts; LinkMesh carries only the configuration and health. Raw values are redacted before egress and never transit LinkMesh at all.

Sensitive data is masked on your infrastructure, before it leaves — never in someone else’s cloud.

How LinkMesh is deployed and secured →

What LinkMesh is — and what it isn’t

What it is

A self-hosted control plane that manages the masking, redaction, and drop processors running in your OpenTelemetry Collectors — standard otelcol-contrib and Grafana Alloy — so sensitive fields are removed on the host, before telemetry is sent.

What it isn’t

It is not a telemetry backend, a data store, or a masking service you send data to. LinkMesh does not ingest, index, or retain your logs, metrics, or traces — the collectors do the masking and send it straight to your own backends. Raw values never transit LinkMesh.

If nothing changes

Left alone, none of this gets cheaper: the volume grows on its own, the data that already left cannot be recalled, and each agent added is one more to remove later.

Once it is running

  • A per-collector bill that a volume spike does not move.
  • Sensitive fields masked on the host, before anything leaves the network.
  • Every config change a diff you can review and roll back.
  • Backends you can swap, because nothing proprietary sits in the path.

Common questions

Where does the PII masking actually run?

On the host, inside your own OpenTelemetry Collector, before any telemetry is sent. LinkMesh renders your masking rules to OTTL and pushes them to the collector over the control plane; the redaction happens in the collector at the edge, so raw values are removed before egress.

Which PII patterns can LinkMesh redact?

Built-in templates cover common formats such as credit card numbers, email addresses, and phone numbers. For everything specific to your systems — account IDs, API tokens, secrets, user identifiers — you write custom OTTL rules targeting exactly those attributes and body fields.

Does my telemetry pass through LinkMesh to be masked?

No. LinkMesh is self-hosted and carries only configuration and health. Masking runs in your own collectors, and your telemetry flows straight from them to your backends — it never transits LinkMesh, so no raw values are ever sent to it.

What is the difference between dropping, redacting, and hashing?

Dropping removes the record or attribute entirely. Redacting replaces the value with a fixed placeholder so the field stays present but the value is gone. Hashing replaces the value with a consistent hash, so the same input stays correlatable across records without exposing the original. You choose per rule.

Can I see what a masking rule does before it goes live?

Yes. LinkMesh previews each rule against real captured records — input, rule, and output side by side — so you see exactly which fields are touched before the rule reaches any collector. You can attach masking at the group level so new collectors inherit it on enrollment.

How is LinkMesh priced?

By managed collector, never by data volume. The first 25 collectors are free after a no-card registration in the OpenSight Customer Portal (5 without one); beyond that it is a flat USD 12.50 · CHF 12.00 · EUR 12.50 per collector per month, billed annually, and the bill stops growing at 200 collectors.

Redact PII where it’s produced — not after it’s indexed

Self-hosted, vendor-neutral, priced per collector. Stand LinkMesh up, preview your masking rules against real records, and stop sensitive data before egress. The first 25 Collectors are free after a no-card registration in the OpenSight Customer Portal (5 without one).

Install the control plane on any Linux VM — Ubuntu / Debian

curl -fsSL https://artifacts.saas.opensight.ch/binaries/linkmesh-server/latest/linkmesh-server_latest_amd64.deb -o linkmesh-server.deb && sudo apt install -y ./linkmesh-server.deb

RHEL / Rocky / AlmaLinux, collector enrollment, and the full walkthrough: Install guide →

Test this in your own environment

Use these maintained guides to move from product evaluation to a working configuration.

Check versions and limitations first