<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Filter syntax options in serverclass.conf in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Filter-syntax-options-in-serverclass-conf/m-p/10659#M533</link>
    <description>&lt;P&gt;Is it possible to use regular expressions for the whitelist/blacklist filters in serverclass.conf? For example:&lt;/P&gt;

&lt;P&gt;whitelist.0=mail[0-9]+.*&lt;/P&gt;</description>
    <pubDate>Mon, 29 Mar 2010 19:50:00 GMT</pubDate>
    <dc:creator>Peter</dc:creator>
    <dc:date>2010-03-29T19:50:00Z</dc:date>
    <item>
      <title>Filter syntax options in serverclass.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-syntax-options-in-serverclass-conf/m-p/10659#M533</link>
      <description>&lt;P&gt;Is it possible to use regular expressions for the whitelist/blacklist filters in serverclass.conf? For example:&lt;/P&gt;

&lt;P&gt;whitelist.0=mail[0-9]+.*&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2010 19:50:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-syntax-options-in-serverclass-conf/m-p/10659#M533</guid>
      <dc:creator>Peter</dc:creator>
      <dc:date>2010-03-29T19:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Filter syntax options in serverclass.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-syntax-options-in-serverclass-conf/m-p/10660#M534</link>
      <description>&lt;P&gt;It is not possible currently (version 4.0). Only &lt;CODE&gt;*&lt;/CODE&gt; as a wildcard for any character can be used.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2010 20:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-syntax-options-in-serverclass-conf/m-p/10660#M534</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-03-29T20:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Filter syntax options in serverclass.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-syntax-options-in-serverclass-conf/m-p/10661#M535</link>
      <description>&lt;P&gt;I see that PCRE expressions have been added as of 4.1, but the mappings confuse me. My current serverclass.conf has name8.&lt;EM&gt;, which mean to match name8.blah and name8.bleh. It would be easier for me to match name[0-9]+..&lt;/EM&gt;, but the docs seem to indicate that '.' is converted to '.' and '&lt;EM&gt;' is converted to '.&lt;/EM&gt;'  Can you add clarity to this?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2010 01:34:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-syntax-options-in-serverclass-conf/m-p/10661#M535</guid>
      <dc:creator>Peter</dc:creator>
      <dc:date>2010-06-29T01:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Filter syntax options in serverclass.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-syntax-options-in-serverclass-conf/m-p/10662#M536</link>
      <description>&lt;P&gt;If regex in these whitelists are anything like the regexp in stanza names, there was a bug in the docs. . means dot, * means anything but slash (meaning filenames only) and ... (three dots) means anything, your usual regex .*&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2010 05:26:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-syntax-options-in-serverclass-conf/m-p/10662#M536</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2010-08-11T05:26:21Z</dc:date>
    </item>
  </channel>
</rss>

