Getting Data In

Blacklist directories?

ustun
Explorer

I'm missing something here:

blacklist = (samba|yum|.gz)

samba is a directory, the others are files.

splunk still tries to monitor samba here, I see it in the output of "splunk list monitor". Also splunkd.log says permission denied for samba, which means it's not ignoring it.

What am I missing? Is there a problem with the regex?

Ustun

Tags (1)
0 Karma

dantimola
Communicator

This answer is late, but for this problem you can just add the stanza below for your inputs.conf

[blacklist://<path>]

Cheers,
Dan

0 Karma

akocak
Contributor

I haven't seen any example that you can blacklist directory yet

0 Karma

ustun
Explorer

It didn't work that way either, I don't see a problem with this simple regex. I guess something else is going on. Will update once resolved.

Ustun

0 Karma

mamaral
Path Finder

try it that: lacklist.0 = complete path of samba folder lacklist.1 = *yum lacklist.2 = *.gz

Amaral

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...