<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: blacklist a string during file monitoring in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/blacklist-a-string-during-file-monitoring/m-p/695580#M115483</link>
    <description>&lt;P&gt;Inputs settings can determine which files to monitor, but cannot filter events out of monitored files.&amp;nbsp; To do that, you need to use props and (optionally) transforms on an indexer or heavy forwarder.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Aug 2024 15:16:01 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-08-07T15:16:01Z</dc:date>
    <item>
      <title>blacklist a string during file monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/blacklist-a-string-during-file-monitoring/m-p/695540#M115480</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I am monitoring blucoat proxy logs via syslog log collection method. My input.conf file is configured to read all logs inside the location opt/splunk/syslog/symantec/bluecoat/*/*.log.&amp;nbsp; below is the current configuration. Now i need to exclude the log which have&amp;nbsp;cs-host=nxtengine.cpga.net.qa from indexing.&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[monitor:///opt/splunk/syslog/symantec/bluecoat/*/*.log]
sourcetype = bluecoat:proxysg:access:syslog
index = cus_XXX
host_segment = 6
disabled = false&lt;/LI-CODE&gt;
&lt;P&gt;Sample raw logs below&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;2024-08-07T14:12:37&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;03:00&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.253.253.44&lt;/SPAN&gt; &lt;SPAN class=""&gt;Bluecoat&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;src=X.x.x.x&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;srcport=53936&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;dst=x.x.x.x&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;dstport=8443&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;username=abcdef$&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;devicetime=&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;07/08/2024:11:12:32&lt;/SPAN&gt; &lt;SPAN class=""&gt;GMT&lt;/SPAN&gt;&lt;SPAN&gt;]|&lt;/SPAN&gt;&lt;SPAN class=""&gt;s-action=TCP_DENIED&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;sc-status=407&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;cs-method=CONNECT&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;time-taken=11&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;sc-bytes=247&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;cs-bytes=816&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;cs-uri-scheme=tcp&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;cs-host=nxtengine.cpga.net.qa&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;cs-uri-path=/&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;cs-uri-query=-&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;cs-uri-extension=-&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;cs-auth-group=-&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;rs&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;Content-Type&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;=-&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;cs&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;User-Agent&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;=Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;cs&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;Referer&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;=-&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;sc-filter-result=DENIED&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;filter-category=none&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;cs-uri=tcp://nxtengine.cpga.net.qa:8443/&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 12:03:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/blacklist-a-string-during-file-monitoring/m-p/695540#M115480</guid>
      <dc:creator>Ashker</dc:creator>
      <dc:date>2024-08-07T12:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: blacklist a string during file monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/blacklist-a-string-during-file-monitoring/m-p/695541#M115481</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 12:24:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/blacklist-a-string-during-file-monitoring/m-p/695541#M115481</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-07T12:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: blacklist a string during file monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/blacklist-a-string-during-file-monitoring/m-p/695580#M115483</link>
      <description>&lt;P&gt;Inputs settings can determine which files to monitor, but cannot filter events out of monitored files.&amp;nbsp; To do that, you need to use props and (optionally) transforms on an indexer or heavy forwarder.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 15:16:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/blacklist-a-string-during-file-monitoring/m-p/695580#M115483</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-08-07T15:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: blacklist a string during file monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/blacklist-a-string-during-file-monitoring/m-p/695589#M115484</link>
      <description>&lt;P&gt;This may also be useful, you can let the already logged files remain and just refine the inputs conf to exclude the logs you don't want monitored and ingested.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-inputs-conf/td-p/598999" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-inputs-conf/td-p/598999&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;In addition to PickleRick's DOC suggestion:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/InputsConf#MONITOR:" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/InputsConf#MONITOR:&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 17:05:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/blacklist-a-string-during-file-monitoring/m-p/695589#M115484</guid>
      <dc:creator>JohnEGones</dc:creator>
      <dc:date>2024-08-07T17:05:56Z</dc:date>
    </item>
  </channel>
</rss>

