<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blacklisting path of inputs.conf for Local Test in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-path-of-inputs-conf-for-Local-Test/m-p/669291#M112221</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;, I believe this is the cause of issue,&lt;BR /&gt;&lt;BR /&gt;from the below snapshot&amp;nbsp;&amp;nbsp;Creator_Process_Name&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; New_Process_Name&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;C:\Program Files (x86)\Tanium\Tanium Client\TaniumClient.exe&lt;/TD&gt;&lt;TD&gt;C:\Windows\System32\cmd.exe&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I excluded the creator processname tanium its newprocess name cmd.exe is also excluded.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Dec 2023 13:06:39 GMT</pubDate>
    <dc:creator>smith_</dc:creator>
    <dc:date>2023-12-06T13:06:39Z</dc:date>
    <item>
      <title>Blacklisting path of inputs.conf for Local Test</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-path-of-inputs-conf-for-Local-Test/m-p/669265#M112217</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm aiming to test event blacklists on my host system locally, but I'm uncertain about the correct location within the inputs.conf file to place these blacklists. Would it be in:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf&lt;/LI&gt;&lt;LI&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\myapp\local\inputs.conf&lt;BR /&gt;&lt;BR /&gt;Thanks...&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Tue, 21 Nov 2023 00:22:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-path-of-inputs-conf-for-Local-Test/m-p/669265#M112217</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-11-21T00:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting path of inputs.conf for Local Test</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-path-of-inputs-conf-for-Local-Test/m-p/669268#M112218</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@smith_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both locations are right.&amp;nbsp;&lt;/P&gt;&lt;P&gt;the first one ... the &lt;SPAN&gt;\etc\system\local\inputs.conf is the default inputs.conf file path. Generally if you dont have different apps, you can use this file alone and specify all files for monitoring, whitelisting and blacklistings.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if you have lots of things for monitoring, it will be better to group them as "apps" and then have their config files in their particular folders. so troubleshooting will become easy.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;then understanding the file precedence&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/9.1.1/Admin/Wheretofindtheconfigurationfiles" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/9.1.1/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 01:37:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-path-of-inputs-conf-for-Local-Test/m-p/669268#M112218</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-11-21T01:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting path of inputs.conf for Local Test</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-path-of-inputs-conf-for-Local-Test/m-p/669291#M112221</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;, I believe this is the cause of issue,&lt;BR /&gt;&lt;BR /&gt;from the below snapshot&amp;nbsp;&amp;nbsp;Creator_Process_Name&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; New_Process_Name&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;C:\Program Files (x86)\Tanium\Tanium Client\TaniumClient.exe&lt;/TD&gt;&lt;TD&gt;C:\Windows\System32\cmd.exe&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I excluded the creator processname tanium its newprocess name cmd.exe is also excluded.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 13:06:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-path-of-inputs-conf-for-Local-Test/m-p/669291#M112221</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-12-06T13:06:39Z</dc:date>
    </item>
  </channel>
</rss>

