The PHP agent default security settings automatically provide security for your APM data to ensure data privacy and to limit the kind of information New Relic receives. You may have business reasons to change these settings.
If you want to restrict the information that New Relic receives, you can enable high-security mode. If high-security mode or the default settings do not work for your business needs, you can apply custom settings.
By default, here is how the New Relic PHP agent handles the following potentially sensitive data:
- Request parameters: The agent does not capture HTTP request parameters.
- HTTPS: The agent communicates with New Relic using HTTPS.
- SQL: The agent sets SQL recording to
obfuscated, which removes the potentially sensitive numeric and string literal values.
- You cannot create custom events.
- The agent strips exception messages from errors.
If you customize security settings, it may impact the security of your application.
If you need different security settings than default or high-security mode, you can customize these settings:
Effects on data security
If you use this to set the name of the audit log file, the agent will log details of messages passed back and forth between the monitored process and the New Relic collector.
You can then evaluate the information that the agent sends to the New Relic collector to see if it includes sensitive information.
Some proxies default to using HTTP, which is a less secure protocol.
By default, you are sending attributes to New Relic. If you do not want to send attributes to New Relic, set this to
If there are specific attribute keys that you do not want to send to New Relic in transaction traces, identify them using
Consider if you want to exclude these potentially sensitive attributes using