<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blacklisting directories without read permission in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299255#M56598</link>
    <description>&lt;P&gt;Hi scottprigge,&lt;BR /&gt;
try to use &lt;CODE&gt;blacklist = lost\+found&lt;/CODE&gt;&lt;BR /&gt;
and then restart Splunk on Forwarder.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 24 Aug 2017 08:33:32 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2017-08-24T08:33:32Z</dc:date>
    <item>
      <title>Blacklisting directories without read permission</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299254#M56597</link>
      <description>&lt;P&gt;Hi. I have configured a 6.5.3 Linux Universal Forwarder with an inputs.conf like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///www/*/logs/access_log*]
disabled = 0
index = web
sourcetype = access_combined
crcSalt = &amp;lt;SOURCE&amp;gt;
blacklist = \.gz$|lost\+found
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I am trying to blacklist a directory named '/www/lost+found' because the splunk user does not have read-permission to this directory. But the blacklist regex isn't working because I am still seeing a &lt;CODE&gt;WARN  FilesystemChangeWatcher - error reading directory "/www/lost+found": Permission denied&lt;/CODE&gt; error in the _internal log. It seems to be ignoring .gz files as I would expect.  Is this an issue with the regex? Or is this more of an order-of-operations type of situation where it needs to read the directory before processing the blacklist?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 20:27:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299254#M56597</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2017-08-23T20:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting directories without read permission</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299255#M56598</link>
      <description>&lt;P&gt;Hi scottprigge,&lt;BR /&gt;
try to use &lt;CODE&gt;blacklist = lost\+found&lt;/CODE&gt;&lt;BR /&gt;
and then restart Splunk on Forwarder.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 08:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299255#M56598</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-24T08:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting directories without read permission</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299256#M56599</link>
      <description>&lt;P&gt;Sorry, maybe I misunderstood something. But I already have that exact blacklist regex included in the stanza of my original post. The difference is that I also need to exclude files ending with a .gz extension so my regex looks like &lt;CODE&gt;\.gz$|lost\+found&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 12:25:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299256#M56599</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2017-08-24T12:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting directories without read permission</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299257#M56600</link>
      <description>&lt;P&gt;Sorry I misunderstood,&lt;BR /&gt;
try with&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;blacklist = \.gz$|lost\+found.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 08:49:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299257#M56600</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-08-25T08:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting directories without read permission</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299258#M56601</link>
      <description>&lt;P&gt;No, that doesn't seem to have made any difference.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 14:39:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299258#M56601</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2017-08-25T14:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting directories without read permission</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299259#M56602</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; blacklist = \.gz$|(lost\+found)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 25 Aug 2017 15:10:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299259#M56602</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-08-25T15:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklisting directories without read permission</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299260#M56603</link>
      <description>&lt;P&gt;Unfortunately no, that didn't work either.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 17:40:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklisting-directories-without-read-permission/m-p/299260#M56603</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2017-08-25T17:40:56Z</dc:date>
    </item>
  </channel>
</rss>

