<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Knowledge Bundle (Searchpeer Bundle)- Replication Blacklist in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle-Searchpeer-Bundle-Replication-Blacklist/m-p/553141#M5897</link>
    <description>&lt;P&gt;Perhaps the manual at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/DistSearch/Limittheknowledgebundlesize#Eliminate_files_from_the_knowledge_bundle" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.0/DistSearch/Limittheknowledgebundlesize#Eliminate_files_from_the_knowledge_bundle &lt;/A&gt;will help.&amp;nbsp; The files to exclude from replication go in the &lt;FONT face="courier new,courier"&gt;[replicationBlacklist]&lt;/FONT&gt; stanza, which is similar to the &lt;FONT face="courier new,courier"&gt;[replicationWhitelist]&lt;/FONT&gt; stanza that is described in greater detail in the same manual.&amp;nbsp; The settings can go into any app, but apply to ALL apps so be careful.&lt;/P&gt;</description>
    <pubDate>Wed, 26 May 2021 13:05:42 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-05-26T13:05:42Z</dc:date>
    <item>
      <title>Knowledge Bundle (Searchpeer Bundle)- Replication Blacklist</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle-Searchpeer-Bundle-Replication-Blacklist/m-p/553118#M5896</link>
      <description>&lt;P&gt;Due to some Performance Issues, Lookup/Dashboard failures, search failures and taking longtime to execute the searches. we have done some troubleshooting and come up with some exclusion list which needs to be blacklist. here I have few questions&lt;BR /&gt;&lt;BR /&gt;1. how to blacklist these exclusion list? what will be the process and procedure that needs to be followed?&lt;BR /&gt;2. where should we blacklist? should we create any global App? is there any specific App or place to do this?&lt;/P&gt;&lt;P&gt;3. most of these are .csv files, Bin and Jar files.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I could see few splunk community answers, but I couldn't see any complete process or any procedure to follow.&lt;/P&gt;&lt;P&gt;Thanks in Advance, Appreciate your help!&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 10:53:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle-Searchpeer-Bundle-Replication-Blacklist/m-p/553118#M5896</guid>
      <dc:creator>mintutivo</dc:creator>
      <dc:date>2021-05-26T10:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Knowledge Bundle (Searchpeer Bundle)- Replication Blacklist</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle-Searchpeer-Bundle-Replication-Blacklist/m-p/553141#M5897</link>
      <description>&lt;P&gt;Perhaps the manual at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/DistSearch/Limittheknowledgebundlesize#Eliminate_files_from_the_knowledge_bundle" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.0/DistSearch/Limittheknowledgebundlesize#Eliminate_files_from_the_knowledge_bundle &lt;/A&gt;will help.&amp;nbsp; The files to exclude from replication go in the &lt;FONT face="courier new,courier"&gt;[replicationBlacklist]&lt;/FONT&gt; stanza, which is similar to the &lt;FONT face="courier new,courier"&gt;[replicationWhitelist]&lt;/FONT&gt; stanza that is described in greater detail in the same manual.&amp;nbsp; The settings can go into any app, but apply to ALL apps so be careful.&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 13:05:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle-Searchpeer-Bundle-Replication-Blacklist/m-p/553141#M5897</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-05-26T13:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Knowledge Bundle (Searchpeer Bundle)- Replication Blacklist</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle-Searchpeer-Bundle-Replication-Blacklist/m-p/553293#M5917</link>
      <description>&lt;P&gt;Hi Rich,&lt;/P&gt;&lt;P&gt;Thanks for providing the info. apart from that, I have few concerns here!&lt;/P&gt;&lt;P&gt;Should I create any App, and add these attributes/values to it (Replication Blacklist)?&lt;/P&gt;&lt;P&gt;OR&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;can we Blacklist directly in Distsearch.conf (from /opt/splunk/etc/system/local on Search Head)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please provide me any such info.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 09:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle-Searchpeer-Bundle-Replication-Blacklist/m-p/553293#M5917</guid>
      <dc:creator>mintutivo</dc:creator>
      <dc:date>2021-05-27T09:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Knowledge Bundle (Searchpeer Bundle)- Replication Blacklist</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle-Searchpeer-Bundle-Replication-Blacklist/m-p/553322#M5918</link>
      <description>&lt;P&gt;You can do it either way.&amp;nbsp; Since the changes affect all apps, I suggest putting the blacklist in etc/system/local.&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 12:31:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Knowledge-Bundle-Searchpeer-Bundle-Replication-Blacklist/m-p/553322#M5918</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-05-27T12:31:30Z</dc:date>
    </item>
  </channel>
</rss>

