<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Whitelist Would not work in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Whitelist-Would-not-work/m-p/37682#M6924</link>
    <description>&lt;P&gt;That is not a valid regex that would match your log file name.  Try:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;whitelist=myserver\.log.*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 27 Apr 2012 07:20:59 GMT</pubDate>
    <dc:creator>araitz</dc:creator>
    <dc:date>2012-04-27T07:20:59Z</dc:date>
    <item>
      <title>Whitelist Would not work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Whitelist-Would-not-work/m-p/37681#M6923</link>
      <description>&lt;P&gt;The following logs in Weblogic are being captured in inputs.conf&lt;/P&gt;

&lt;P&gt;mydomain.log1123213123 mydomain.log4353245254&lt;/P&gt;

&lt;P&gt;myserver.log3423423423 myserver.log566999999&lt;/P&gt;

&lt;P&gt;access.log34324324324 access.log234324324&lt;/P&gt;

&lt;P&gt;We did this using the following whitelist -&amp;gt;&lt;/P&gt;

&lt;P&gt;[ monitor://c:\bea\user_projects\domains\mydomain ]&lt;/P&gt;

&lt;P&gt;disabled = 0 &lt;/P&gt;

&lt;P&gt;whitelist = mydomain.log*&lt;/P&gt;

&lt;P&gt;index = main &lt;/P&gt;

&lt;P&gt;sourcetype = mydomain&lt;/P&gt;

&lt;P&gt;[ monitor://c:\bea\user_projects\domains\mydomain\myserver ]&lt;/P&gt;

&lt;P&gt;disabled = 0 &lt;/P&gt;

&lt;P&gt;whitelist = myserver.log*&lt;/P&gt;

&lt;P&gt;index = main &lt;/P&gt;

&lt;P&gt;sourcetype = myserver&lt;/P&gt;

&lt;P&gt;But that does not seem to be helping.&lt;/P&gt;

&lt;P&gt;Any suggestions ? &lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2012 23:14:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Whitelist-Would-not-work/m-p/37681#M6923</guid>
      <dc:creator>asarolkar</dc:creator>
      <dc:date>2012-04-26T23:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelist Would not work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Whitelist-Would-not-work/m-p/37682#M6924</link>
      <description>&lt;P&gt;That is not a valid regex that would match your log file name.  Try:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;whitelist=myserver\.log.*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 27 Apr 2012 07:20:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Whitelist-Would-not-work/m-p/37682#M6924</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2012-04-27T07:20:59Z</dc:date>
    </item>
  </channel>
</rss>

