<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can i use whitelist to allow only the required data from eventlog? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-use-whitelist-to-allow-only-the-required-data-from/m-p/42535#M7939</link>
    <description>&lt;P&gt;Thanks Bob! This will help with my implementation.&lt;/P&gt;</description>
    <pubDate>Wed, 22 May 2013 11:31:55 GMT</pubDate>
    <dc:creator>linu1988</dc:creator>
    <dc:date>2013-05-22T11:31:55Z</dc:date>
    <item>
      <title>How can i use whitelist to allow only the required data from eventlog?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-use-whitelist-to-allow-only-the-required-data-from/m-p/42532#M7936</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
i would like to forward only my program related data from e.g. Program A: error occurred at step 6!!&lt;/P&gt;

&lt;P&gt;How can i use the whitelist and blacklist to get rid of the unnecessary event logs.&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2013 09:28:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-use-whitelist-to-allow-only-the-required-data-from/m-p/42532#M7936</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2013-05-22T09:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: How can i use whitelist to allow only the required data from eventlog?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-use-whitelist-to-allow-only-the-required-data-from/m-p/42533#M7937</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2013 09:32:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-use-whitelist-to-allow-only-the-required-data-from/m-p/42533#M7937</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-05-22T09:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: How can i use whitelist to allow only the required data from eventlog?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-use-whitelist-to-allow-only-the-required-data-from/m-p/42534#M7938</link>
      <description>&lt;P&gt;Whitelists and blacklists are only used at inputs phase and match against source names, normally file names or folders. It sounds like you want to discard individual events which can not be done until parsing phase. &lt;/P&gt;

&lt;P&gt;This must be done on the indexer and the link Ayn provided explains how to do this.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2013 10:01:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-use-whitelist-to-allow-only-the-required-data-from/m-p/42534#M7938</guid>
      <dc:creator>BobM</dc:creator>
      <dc:date>2013-05-22T10:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: How can i use whitelist to allow only the required data from eventlog?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-use-whitelist-to-allow-only-the-required-data-from/m-p/42535#M7939</link>
      <description>&lt;P&gt;Thanks Bob! This will help with my implementation.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2013 11:31:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-use-whitelist-to-allow-only-the-required-data-from/m-p/42535#M7939</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2013-05-22T11:31:55Z</dc:date>
    </item>
  </channel>
</rss>

