Dear Experts,
I am trying to blacklist a log file.
My Stanza looks like this which is located in /opt/splunkforwarder/etc/apps/search/local/inputs.conf

blacklist = /www/a/logs/hotimportexport.log
disabled = false
index = main
sourcetype = Test

Can someone please tell me why my blacklist is not working?


Try removing the full path name from the blacklist attribute.

blacklist = hotimportexport.log 
disabled = false 
index = main 
sourcetype = Test
