<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trying to properly format a blacklist for imported files. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-properly-format-a-blacklist-for-imported-files/m-p/469816#M80808</link>
    <description>&lt;P&gt;I have configured multiple Data Inputs, pointing at folders such as /mnt/DataInput1 etc.  There is a lot of noise so tried following the following links to add a blacklist to the inputs.conf for the input, to restrict junk data such as Level=INFO type linux data. &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata?r=searchtip" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata?r=searchtip&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Example input:&lt;BR /&gt;
[monitor:///mnt/blob/XXXXXXXXXX/logs]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = customer_XXXX_XXXXXXXX&lt;BR /&gt;
blacklist = Level="(INFO)"&lt;/P&gt;

&lt;P&gt;Unfortunately after several tries, and after making a change, restarting Splunk to see the change, then waiting several hours for the Data Inputs page to queue up the number of files, it still doesn't work. &lt;/P&gt;

&lt;P&gt;Can anyone please shed some insight into what I'm doing wrong please? &lt;BR /&gt;
Ultimately I'd like to do something like:&lt;/P&gt;

&lt;P&gt;blacklist = Level="(INFO)"|coderef="(salt*)|"consul)"&lt;/P&gt;

&lt;P&gt;Where as you can see above, I want to blacklist =different event types. &lt;/P&gt;

&lt;P&gt;Help?&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 05:36:19 GMT</pubDate>
    <dc:creator>mpresseau</dc:creator>
    <dc:date>2020-09-30T05:36:19Z</dc:date>
    <item>
      <title>Trying to properly format a blacklist for imported files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-properly-format-a-blacklist-for-imported-files/m-p/469816#M80808</link>
      <description>&lt;P&gt;I have configured multiple Data Inputs, pointing at folders such as /mnt/DataInput1 etc.  There is a lot of noise so tried following the following links to add a blacklist to the inputs.conf for the input, to restrict junk data such as Level=INFO type linux data. &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata?r=searchtip" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata?r=searchtip&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Example input:&lt;BR /&gt;
[monitor:///mnt/blob/XXXXXXXXXX/logs]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = customer_XXXX_XXXXXXXX&lt;BR /&gt;
blacklist = Level="(INFO)"&lt;/P&gt;

&lt;P&gt;Unfortunately after several tries, and after making a change, restarting Splunk to see the change, then waiting several hours for the Data Inputs page to queue up the number of files, it still doesn't work. &lt;/P&gt;

&lt;P&gt;Can anyone please shed some insight into what I'm doing wrong please? &lt;BR /&gt;
Ultimately I'd like to do something like:&lt;/P&gt;

&lt;P&gt;blacklist = Level="(INFO)"|coderef="(salt*)|"consul)"&lt;/P&gt;

&lt;P&gt;Where as you can see above, I want to blacklist =different event types. &lt;/P&gt;

&lt;P&gt;Help?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:36:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-properly-format-a-blacklist-for-imported-files/m-p/469816#M80808</guid>
      <dc:creator>mpresseau</dc:creator>
      <dc:date>2020-09-30T05:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to properly format a blacklist for imported files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-properly-format-a-blacklist-for-imported-files/m-p/469817#M80809</link>
      <description>&lt;P&gt;That's not what blacklisting does.  The blacklist feature in a monitor statement tells Splunk to ignore any &lt;EM&gt;file&lt;/EM&gt; that matches the given expression.  It's often used to skip .gz files, for example.&lt;/P&gt;

&lt;P&gt;Filtering certain events within a file is a different feature, which is implemented using transforms.  See &lt;A href="https://answers.splunk.com/answers/719162/how-do-i-use-propsconf-and-transformsconf-to-filte.html"&gt;https://answers.splunk.com/answers/719162/how-do-i-use-propsconf-and-transformsconf-to-filte.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 21:08:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-properly-format-a-blacklist-for-imported-files/m-p/469817#M80809</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-01T21:08:18Z</dc:date>
    </item>
  </channel>
</rss>

