<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: monitor blacklist Question in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110357#M23176</link>
    <description>&lt;P&gt;Can we make this in single like (Just example, dont know in splunk)&lt;/P&gt;

&lt;P&gt;blacklist = erlDirService*.log&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jan 2014 09:12:49 GMT</pubDate>
    <dc:creator>rameshlpatel</dc:creator>
    <dc:date>2014-01-13T09:12:49Z</dc:date>
    <item>
      <title>monitor blacklist Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110353#M23172</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have log file with name of erlDirService_log.log and erlDirService_error.log.&lt;/P&gt;

&lt;P&gt;I want to put this in blacklist in monitor stanza(inputs.conf).&lt;/P&gt;

&lt;P&gt;So How should I do this ?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:38:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110353#M23172</guid>
      <dc:creator>rameshlpatel</dc:creator>
      <dc:date>2020-09-28T15:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: monitor blacklist Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110354#M23173</link>
      <description>&lt;P&gt;What did you try that didn't work? What in the docs is unclear?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 08:26:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110354#M23173</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-01-13T08:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: monitor blacklist Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110355#M23174</link>
      <description>&lt;P&gt;I read the doc but its uncleared. I have to put this directly on production so i didnt try. I want to sure at first time.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 08:32:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110355#M23174</guid>
      <dc:creator>rameshlpatel</dc:creator>
      <dc:date>2014-01-13T08:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: monitor blacklist Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110356#M23175</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;[monitor:///your/path]
blacklist = erlDirService_log\.log|erlDirService_error\.log
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 13 Jan 2014 09:09:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110356#M23175</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-01-13T09:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: monitor blacklist Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110357#M23176</link>
      <description>&lt;P&gt;Can we make this in single like (Just example, dont know in splunk)&lt;/P&gt;

&lt;P&gt;blacklist = erlDirService*.log&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 09:12:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110357#M23176</guid>
      <dc:creator>rameshlpatel</dc:creator>
      <dc:date>2014-01-13T09:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: monitor blacklist Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110358#M23177</link>
      <description>&lt;P&gt;Yes and no - you can definitely do wildcarding, but it needs to be in regex syntax. Like &lt;CODE&gt;erlDirService.*\.log&lt;/CODE&gt;. But if you're doing this in a production environment and don't really know what you're doing, I would suggest you to read up on how this works.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 09:18:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-blacklist-Question/m-p/110358#M23177</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-01-13T09:18:08Z</dc:date>
    </item>
  </channel>
</rss>

