Getting Data In

Blacklist regular expression not working

Explorer

I want to blacklist below 2 files:

opfe-runautostat.log
opfe-proteusprod_archive
.log

  • here can be any number/characters

I used below regex but the same is not working. Can someone please help.

blacklist = .(runautostat|proteusprod_archive).log$

Tags (1)
0 Karma

inputs.conf?

You should include one of these keys: http://docs.splunk.com/Documentation/Splunk/6.4.2/Data/MonitorWindowseventlogdata#Create_advanced_fi...

so yours might be something like:
blacklist1 = Message=%.(runautostat|proteusprod_archive)..log%

depending on where the string is in the message field, in might also be
blacklist1 = Message=%^.(runautostat|proteusprod_archive)..log$%

0 Karma

SplunkTrust
SplunkTrust

Can you please post your filename and regex with Code Sample format (Please use button 101010)

0 Karma

Contributor

shouldn't it be

.(run_autostat|proteus_prod_archive).*\.log$