<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure blacklist in inputs.conf file on Linux? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-blacklist-in-inputs-conf-file-on-Linux/m-p/208265#M41047</link>
    <description>&lt;P&gt;There are a few ways to do this in inputs.conf.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Apply it to a monitor like this:&lt;/STRONG&gt;&lt;BR /&gt;
[monitor:///data/splunk/test/test*.csv]&lt;BR /&gt;
blacklist = 538|540|576&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Apply to all monitors and creates an error if a monitor returns a blacklisted file.&lt;/STRONG&gt;&lt;BR /&gt;
[blacklist:]&lt;BR /&gt;
* Protect files on the filesystem from being indexed or previewed.&lt;BR /&gt;
* Splunk will treat a file as blacklisted if it starts with any of the defined blacklisted .&lt;BR /&gt;
* The preview endpoint will return and error when asked to preview a blacklisted file. &lt;BR /&gt;
* The oneshot endpoint and command will also return an error.&lt;BR /&gt;
* When a blacklisted file is monitored (monitor:// or batch://), filestatus endpoint will show an error.&lt;BR /&gt;
* For fschange with sendFullEvent option enabled, contents of backlisted files will not be indexed.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;I'm guessing you've already seen this:&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/119493/parameter-blacklist-in-inputs-conf.html"&gt;http://answers.splunk.com/answers/119493/parameter-blacklist-in-inputs-conf.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Sep 2015 20:47:08 GMT</pubDate>
    <dc:creator>jaredlaney</dc:creator>
    <dc:date>2015-09-09T20:47:08Z</dc:date>
    <item>
      <title>How to configure blacklist in inputs.conf file on Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-blacklist-in-inputs-conf-file-on-Linux/m-p/208264#M41046</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;We have Splunk forwarder on a Linux platform. I wanted to add a blacklist to my inputs.conf file. Please help me with command which helps me to add this entry to my existing configured monitor.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2015 19:30:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-blacklist-in-inputs-conf-file-on-Linux/m-p/208264#M41046</guid>
      <dc:creator>chris1</dc:creator>
      <dc:date>2015-09-09T19:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure blacklist in inputs.conf file on Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-blacklist-in-inputs-conf-file-on-Linux/m-p/208265#M41047</link>
      <description>&lt;P&gt;There are a few ways to do this in inputs.conf.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Apply it to a monitor like this:&lt;/STRONG&gt;&lt;BR /&gt;
[monitor:///data/splunk/test/test*.csv]&lt;BR /&gt;
blacklist = 538|540|576&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Apply to all monitors and creates an error if a monitor returns a blacklisted file.&lt;/STRONG&gt;&lt;BR /&gt;
[blacklist:]&lt;BR /&gt;
* Protect files on the filesystem from being indexed or previewed.&lt;BR /&gt;
* Splunk will treat a file as blacklisted if it starts with any of the defined blacklisted .&lt;BR /&gt;
* The preview endpoint will return and error when asked to preview a blacklisted file. &lt;BR /&gt;
* The oneshot endpoint and command will also return an error.&lt;BR /&gt;
* When a blacklisted file is monitored (monitor:// or batch://), filestatus endpoint will show an error.&lt;BR /&gt;
* For fschange with sendFullEvent option enabled, contents of backlisted files will not be indexed.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;I'm guessing you've already seen this:&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/119493/parameter-blacklist-in-inputs-conf.html"&gt;http://answers.splunk.com/answers/119493/parameter-blacklist-in-inputs-conf.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2015 20:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-blacklist-in-inputs-conf-file-on-Linux/m-p/208265#M41047</guid>
      <dc:creator>jaredlaney</dc:creator>
      <dc:date>2015-09-09T20:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure blacklist in inputs.conf file on Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-blacklist-in-inputs-conf-file-on-Linux/m-p/208266#M41048</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;I want the Linux command to add this blacklist to my existing monitor log path.&lt;/P&gt;

&lt;P&gt;e.g ./splunk edit monitor \app\log -index test&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2015 21:04:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-blacklist-in-inputs-conf-file-on-Linux/m-p/208266#M41048</guid>
      <dc:creator>chris1</dc:creator>
      <dc:date>2015-09-09T21:04:26Z</dc:date>
    </item>
  </channel>
</rss>

