<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to acknowledge the blacklist working or not ?? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-acknowledge-the-blacklist-working-or-not/m-p/658778#M27493</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've recently applied a blacklist file path regex to one of the apps inputs.conf in the serverclass on the host in DS. How can I determine&amp;nbsp; it's working or not?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Sep 2023 17:03:51 GMT</pubDate>
    <dc:creator>AL3Z</dc:creator>
    <dc:date>2023-09-26T17:03:51Z</dc:date>
    <item>
      <title>How to acknowledge the blacklist working or not ??</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-acknowledge-the-blacklist-working-or-not/m-p/658778#M27493</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've recently applied a blacklist file path regex to one of the apps inputs.conf in the serverclass on the host in DS. How can I determine&amp;nbsp; it's working or not?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 17:03:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-acknowledge-the-blacklist-working-or-not/m-p/658778#M27493</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-09-26T17:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to acknowledge the blacklist working or not ??</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-acknowledge-the-blacklist-working-or-not/m-p/658779#M27494</link>
      <description>&lt;P&gt;If you no longer see data from the blocked data source then the denylist is working.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 17:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-acknowledge-the-blacklist-working-or-not/m-p/658779#M27494</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-09-26T17:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to acknowledge the blacklist working or not ??</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-acknowledge-the-blacklist-working-or-not/m-p/658780#M27495</link>
      <description>&lt;P&gt;Can you pls share the spl command.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 17:35:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-acknowledge-the-blacklist-working-or-not/m-p/658780#M27495</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-09-26T17:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to acknowledge the blacklist working or not ??</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-acknowledge-the-blacklist-working-or-not/m-p/658784#M27496</link>
      <description>&lt;P&gt;You just search for events which have your file(s) as source field value. If they stopped being ingested at some point your blacklisting works. Unless of course you have some additional config overwriting the source field but then it's up to you to find those events - we don't know your setup.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 07:24:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-acknowledge-the-blacklist-working-or-not/m-p/658784#M27496</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-09-27T07:24:07Z</dc:date>
    </item>
  </channel>
</rss>

