<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is a specific file type still being indexed with my inputs.conf whitelist configuration? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-a-specific-file-type-still-being-indexed-with-my-inputs/m-p/203558#M40208</link>
    <description>&lt;P&gt;The proper regular expression for the whitelist is&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;whitelist = (.*access\.log$|.*stash\.log$|.*mail\.log$|.*profiler\.log$|.*debug\.log$|.*plugin\.log$|.*codesearch\.log$|\.out$)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The &lt;CODE&gt;*&lt;/CODE&gt; alone just means "match an asterisk" in regular expressions. While Splunk does sometime allow a mix of globbing and regular expressions, don't do it here...&lt;/P&gt;</description>
    <pubDate>Wed, 02 Sep 2015 19:10:08 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2015-09-02T19:10:08Z</dc:date>
    <item>
      <title>Why is a specific file type still being indexed with my inputs.conf whitelist configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-a-specific-file-type-still-being-indexed-with-my-inputs/m-p/203557#M40207</link>
      <description>&lt;P&gt;Here's my stanza:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///opt/stash/logs/]
blacklist = \.gz$
disabled = false
followTail = 0
index = stash_pp
sourcetype = log4j
whitelist = (*access\.log$|*stash\.log$|*mail\.log$|*profiler\.log$|*debug\.log$|*plugin\.log$|*codesearch\.log$|\.out$)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'm getting this file type &lt;CODE&gt;atlassian-stash-access-2015-08-31.0.log&lt;/CODE&gt; which should have been excluded with the whitelist specification. Is there something wrong with the syntax?&lt;/P&gt;

&lt;P&gt;Any help would be appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2015 16:52:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-a-specific-file-type-still-being-indexed-with-my-inputs/m-p/203557#M40207</guid>
      <dc:creator>mlaufenb</dc:creator>
      <dc:date>2015-09-02T16:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why is a specific file type still being indexed with my inputs.conf whitelist configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-a-specific-file-type-still-being-indexed-with-my-inputs/m-p/203558#M40208</link>
      <description>&lt;P&gt;The proper regular expression for the whitelist is&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;whitelist = (.*access\.log$|.*stash\.log$|.*mail\.log$|.*profiler\.log$|.*debug\.log$|.*plugin\.log$|.*codesearch\.log$|\.out$)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The &lt;CODE&gt;*&lt;/CODE&gt; alone just means "match an asterisk" in regular expressions. While Splunk does sometime allow a mix of globbing and regular expressions, don't do it here...&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2015 19:10:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-a-specific-file-type-still-being-indexed-with-my-inputs/m-p/203558#M40208</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2015-09-02T19:10:08Z</dc:date>
    </item>
  </channel>
</rss>

