<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is the best way to blacklist, in GUI compared with inputs.conf? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-blacklist-in-GUI-compared-with-inputs/m-p/334521#M61849</link>
    <description>&lt;P&gt;We have a cluster of three indexers, a Cluster Master, a Search Head/License Master, and a Heavy forwarder.  What is the best way to blacklist, or whitelist, certain classes of input data?  In the Cluster Master GUI, or through the input.cnfg on the Forwarder?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sid Bastani&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jan 2018 14:26:57 GMT</pubDate>
    <dc:creator>saeedb101</dc:creator>
    <dc:date>2018-01-25T14:26:57Z</dc:date>
    <item>
      <title>What is the best way to blacklist, in GUI compared with inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-blacklist-in-GUI-compared-with-inputs/m-p/334521#M61849</link>
      <description>&lt;P&gt;We have a cluster of three indexers, a Cluster Master, a Search Head/License Master, and a Heavy forwarder.  What is the best way to blacklist, or whitelist, certain classes of input data?  In the Cluster Master GUI, or through the input.cnfg on the Forwarder?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sid Bastani&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 14:26:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-blacklist-in-GUI-compared-with-inputs/m-p/334521#M61849</guid>
      <dc:creator>saeedb101</dc:creator>
      <dc:date>2018-01-25T14:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to blacklist, in GUI compared with inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-blacklist-in-GUI-compared-with-inputs/m-p/334522#M61850</link>
      <description>&lt;P&gt;Can you clarify ?&lt;BR /&gt;
"way to blacklist, or whitelist, certain classes of input data"&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;to block a log file, the best is to configure the inputs.conf on the forwarders, to skip the files (blacklists and strict monitor paths)&lt;/LI&gt;
&lt;LI&gt;to block some windows events (wineventlog), the best is to setup eventcode or regex blacklists in inputs.conf on the windows forwarder. &lt;/LI&gt;
&lt;LI&gt;otherwise, to drop events (but not all), you have to look at nullQueue filtering, and setup the filters (in props.conf and transforms.conf)  on the servers parsing the logs:  indexers, or heavy forwarders ( or for special indexed_extractions sourcetypes, on the forwarders)
see : 
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:48:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-blacklist-in-GUI-compared-with-inputs/m-p/334522#M61850</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2020-09-29T17:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to blacklist, in GUI compared with inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-blacklist-in-GUI-compared-with-inputs/m-p/334523#M61851</link>
      <description>&lt;P&gt;Thank you for your answer.  I am really curious to find out why it is not a good idea to use the GUI for blacklisting or whitelisting?  You know, through "Server Classes", "Clients", and "Apps"?  Don't we obtain the same results when we use the "Include (Whitelist)" and "Exclude (Blacklist" GUI page?&lt;/P&gt;

&lt;P&gt;Your advice would be very much appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 18:38:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-blacklist-in-GUI-compared-with-inputs/m-p/334523#M61851</guid>
      <dc:creator>saeedb101</dc:creator>
      <dc:date>2018-01-25T18:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to blacklist, in GUI compared with inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-blacklist-in-GUI-compared-with-inputs/m-p/334524#M61852</link>
      <description>&lt;P&gt;I see, when you meant the GUI, you were referring to the "forwarder management/deployment server" UI.&lt;/P&gt;

&lt;P&gt;Then yes, you can configure your inputs filters from there, as they are the ones that will be pushed to the deployment clients (i.e. the forwarders, in inputs.conf)&lt;/P&gt;

&lt;P&gt;Remark : do not get confused between the whitelist/backlist on the inputs monitor paths, and the whitelist/blacklist on the hostnames used to apply classes to particular subset of forwarders/deploymentclients.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 18:48:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-blacklist-in-GUI-compared-with-inputs/m-p/334524#M61852</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2018-01-25T18:48:37Z</dc:date>
    </item>
  </channel>
</rss>

