<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Monitor Whitelist File extensions in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Whitelist-File-extensions/m-p/36652#M6755</link>
    <description>&lt;P&gt;Hey guys, I guess this is a simple question but all the answers I look at seem very complicated for what I want.&lt;BR /&gt;
I want splunk to do a monitor on C:\Program Files on extensions *.exe, *.com, *.scr and *.dll&lt;/P&gt;

&lt;P&gt;But when I try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://C:\Program Files]
sourcetype = fileExtensions
whitelist = *.exe, *.dll, *.scr, *.com
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I get ALL the files in Program Files appearing in the Splunk search.&lt;/P&gt;

&lt;P&gt;I guess I am doing whitelisting wrong, any help?&lt;/P&gt;</description>
    <pubDate>Fri, 16 Nov 2012 09:14:07 GMT</pubDate>
    <dc:creator>SplunkUser5888</dc:creator>
    <dc:date>2012-11-16T09:14:07Z</dc:date>
    <item>
      <title>Monitor Whitelist File extensions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Whitelist-File-extensions/m-p/36652#M6755</link>
      <description>&lt;P&gt;Hey guys, I guess this is a simple question but all the answers I look at seem very complicated for what I want.&lt;BR /&gt;
I want splunk to do a monitor on C:\Program Files on extensions *.exe, *.com, *.scr and *.dll&lt;/P&gt;

&lt;P&gt;But when I try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://C:\Program Files]
sourcetype = fileExtensions
whitelist = *.exe, *.dll, *.scr, *.com
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I get ALL the files in Program Files appearing in the Splunk search.&lt;/P&gt;

&lt;P&gt;I guess I am doing whitelisting wrong, any help?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2012 09:14:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Whitelist-File-extensions/m-p/36652#M6755</guid>
      <dc:creator>SplunkUser5888</dc:creator>
      <dc:date>2012-11-16T09:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Whitelist File extensions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Whitelist-File-extensions/m-p/36653#M6756</link>
      <description>&lt;P&gt;Hi M-A &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;whitelist and blacklist are not a list of values, but a regular expression.&lt;BR /&gt;
Have a look at the bottom of this page: &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/data/Specifyinputpathswithwildcards"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/data/Specifyinputpathswithwildcards&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2012 16:31:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Whitelist-File-extensions/m-p/36653#M6756</guid>
      <dc:creator>Mathieu_Dessus</dc:creator>
      <dc:date>2012-11-16T16:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Whitelist File extensions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Whitelist-File-extensions/m-p/36654#M6757</link>
      <description>&lt;P&gt;Salut, thanks, I couldn't find that document&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2012 08:41:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Whitelist-File-extensions/m-p/36654#M6757</guid>
      <dc:creator>SplunkUser5888</dc:creator>
      <dc:date>2012-11-19T08:41:19Z</dc:date>
    </item>
  </channel>
</rss>

