Getting Data In

How to blacklist a single source path on a universal forwarder?

prakash007
Builder

I have the monitor stanza on one of my Universal Forwarders.....I tried to blacklist a particular JVM from which the logs are not required to be monitored. Any help would be appreciated on this.

inputs.conf

    [monitor:///opt/server/webservers/*/logs/access*.log]
    sourcetype=access_logs
    blacklist=\/opt\/server\/webservers\/JVM_DEV\/logs\/access*\.log
    crcSalt = <SOURCE>
    index=devint2
0 Karma
1 Solution

prakash007
Builder

some how this worked for me as my logs might be in 2 different formats

/opt/server/webservers/JVM_DEV/logs/access.20160203000000.log
/opt/server/webservers/JVM_DEV/logs/access20160203000000.log

blacklist=\/opt\/server\/webservers\/JVM_DEV\/logs\/access\.?\d+\.log

View solution in original post

0 Karma

prakash007
Builder

some how this worked for me as my logs might be in 2 different formats

/opt/server/webservers/JVM_DEV/logs/access.20160203000000.log
/opt/server/webservers/JVM_DEV/logs/access20160203000000.log

blacklist=\/opt\/server\/webservers\/JVM_DEV\/logs\/access\.?\d+\.log
0 Karma

ddrillic
Ultra Champion

.? takes care of the optional dot...

0 Karma

woodcock
Esteemed Legend

Like this:

    blacklist=\/opt\/server\/webservers\/JVM_DEV\/logs\/access[^\.]*\.log
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk &#43; Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...