<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error when adding new whitelist in inputs.conf in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Error-when-adding-new-whitelist-in-inputs-conf/m-p/508941#M9305</link>
    <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163905"&gt;@harsmarvania57&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for the answer. We made some changes to our config and combined the whitelist where possible.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jul 2020 22:45:31 GMT</pubDate>
    <dc:creator>azrad</dc:creator>
    <dc:date>2020-07-13T22:45:31Z</dc:date>
    <item>
      <title>Error when adding new whitelist in inputs.conf</title>
      <link>https://community.splunk.com/t5/Alerting/Error-when-adding-new-whitelist-in-inputs-conf/m-p/508212#M9274</link>
      <description>&lt;P&gt;Hi Splunk Community&lt;/P&gt;&lt;P&gt;We have created few whitelist in our inputs.conf file. It was all fine until i try to enter the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="c"&gt;whitelist10=Type="Information" SourceName="Customer.Service" Message="*Request Info:ContactCustomer - CreateNewContact*"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;after restarting my splunk, i get the following:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Invalid key in stanza [WinEventLog://Application] in C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf, line 38: whitelist12 (value: Type="Information" SourceName="&lt;SPAN&gt;Customer.Service&lt;/SPAN&gt;&lt;SPAN&gt;" Message="&lt;SPAN&gt;*Request Info:ContactCustomer - CreateNewContact*&lt;/SPAN&gt;").&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;and it gives me the following:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Did you mean 'whitelist'?&lt;/DIV&gt;&lt;DIV&gt;Did you mean 'whitelist1'?&lt;/DIV&gt;&lt;DIV&gt;Did you mean 'whitelist2'?&lt;/DIV&gt;&lt;DIV&gt;Did you mean 'whitelist3'?&lt;/DIV&gt;&lt;DIV&gt;Did you mean 'whitelist4'?&lt;/DIV&gt;&lt;DIV&gt;Did you mean 'whitelist5'?&lt;/DIV&gt;&lt;DIV&gt;Did you mean 'whitelist6'?&lt;/DIV&gt;&lt;DIV&gt;Did you mean 'whitelist7'?&lt;/DIV&gt;&lt;DIV&gt;Did you mean 'whitelist8'?&lt;/DIV&gt;&lt;DIV&gt;Did you mean 'whitelist9'?&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a limit to number of whitelist we can create?&lt;/P&gt;&lt;P&gt;Or what is the next correct key to use after whitelist9 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks!!&lt;/P&gt;&lt;P&gt;Azrad&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 09 Jul 2020 01:50:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Error-when-adding-new-whitelist-in-inputs-conf/m-p/508212#M9274</guid>
      <dc:creator>azrad</dc:creator>
      <dc:date>2020-07-09T01:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Error when adding new whitelist in inputs.conf</title>
      <link>https://community.splunk.com/t5/Alerting/Error-when-adding-new-whitelist-in-inputs-conf/m-p/508256#M9279</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes there is limitation when you specify whitelist/blacklist for Windows Event Montitoring&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.4/Admin/Inputsconf#Windows_Event_Log_Monitor" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.4/Admin/Inputsconf#Windows_Event_Log_Monitor&lt;/A&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;* Numbered whitelist settings are permitted from 1 to 9, so whitelist1 through
  whitelist9 and blacklist1 through blacklist9 are supported.
* If no whitelist or blacklist rules are present, the input reads all events.&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 09 Jul 2020 09:04:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Error-when-adding-new-whitelist-in-inputs-conf/m-p/508256#M9279</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-07-09T09:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Error when adding new whitelist in inputs.conf</title>
      <link>https://community.splunk.com/t5/Alerting/Error-when-adding-new-whitelist-in-inputs-conf/m-p/508941#M9305</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163905"&gt;@harsmarvania57&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for the answer. We made some changes to our config and combined the whitelist where possible.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 22:45:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Error-when-adding-new-whitelist-in-inputs-conf/m-p/508941#M9305</guid>
      <dc:creator>azrad</dc:creator>
      <dc:date>2020-07-13T22:45:31Z</dc:date>
    </item>
  </channel>
</rss>

