<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How come [replicationBlacklist] is not working? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-come-replicationBlacklist-is-not-working/m-p/382740#M93899</link>
    <description>&lt;P&gt;The replicationBlacklist support regex but it appends "$SPLUNK_HOME/etc" to the regex you configured. i.e, SPLUNK_HOME=/opt/splunk&lt;BR /&gt;
When splunk applies the regex above, it would be like "/opt/splunk/&lt;A href="https://community.splunk.com/backups" target="_blank"&gt;\/_.-&lt;/A&gt;[_.-\/] ", which is the reason your lookup files are not filtered out by the blacklist.&lt;/P&gt;

&lt;P&gt;Please try the below;&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;[replicationBlacklist]&lt;BR /&gt;
blacklist_lookups = apps/*/lookups/lookup_file_backups/*.csv&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 21:58:11 GMT</pubDate>
    <dc:creator>sylim_splunk</dc:creator>
    <dc:date>2020-09-29T21:58:11Z</dc:date>
    <item>
      <title>How come [replicationBlacklist] is not working?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-come-replicationBlacklist-is-not-working/m-p/382739#M93898</link>
      <description>&lt;P&gt;We have a list of large lookup files that are not supposed to be included in the search bundles. Their configurations are below. However, we have found that they are still in the bundle.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[replicationBlacklist] 
blacklist_lookups = [\/\_\.\-](backups)[_\.\-\/\\]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The files looks like this in the file system;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;apps/DA-ESS-AccessProtection/lookups/lookup_file_backups/abc2.csv
apps/DA-ESS-AccessProtection/lookups/lookup_file_backups/bcd1.csv
apps/search/lookups/lookup_file_backups/abcd5.csv
apps/DA-ESS-ThreatIntelligence/lookups/lookup_file_backups/abcd4
apps/SplunkEnterpriseSecuritySuite/lookups/lookup_file_backups/xyz10.csv
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I've checked this regex in "regex101.com" which works fine for the above.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 18:14:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-come-replicationBlacklist-is-not-working/m-p/382739#M93898</guid>
      <dc:creator>sylim_splunk</dc:creator>
      <dc:date>2018-11-12T18:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: How come [replicationBlacklist] is not working?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-come-replicationBlacklist-is-not-working/m-p/382740#M93899</link>
      <description>&lt;P&gt;The replicationBlacklist support regex but it appends "$SPLUNK_HOME/etc" to the regex you configured. i.e, SPLUNK_HOME=/opt/splunk&lt;BR /&gt;
When splunk applies the regex above, it would be like "/opt/splunk/&lt;A href="https://community.splunk.com/backups" target="_blank"&gt;\/_.-&lt;/A&gt;[_.-\/] ", which is the reason your lookup files are not filtered out by the blacklist.&lt;/P&gt;

&lt;P&gt;Please try the below;&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;[replicationBlacklist]&lt;BR /&gt;
blacklist_lookups = apps/*/lookups/lookup_file_backups/*.csv&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-come-replicationBlacklist-is-not-working/m-p/382740#M93899</guid>
      <dc:creator>sylim_splunk</dc:creator>
      <dc:date>2020-09-29T21:58:11Z</dc:date>
    </item>
  </channel>
</rss>

