I have added my log folder in Splunk monitoring. I want to exclude the files that start with Test from Splunk monitoring. Is it possible? Please suggest me a solution on this. There are so many unwanted files that are getting created in that log folder and it is getting uploaded into Splunk and affecting daily license usage.
Configure your exclusion in props.conf file :
To exclude this file from being picked up by the forwarder, I think you can use a blacklist http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/Whitelistorblacklistspecificincomingdata
blacklist = (test$)
I think we need to update in inputs.conf right? Also I tried blacklist = (test$) it is not working as expected. am still seeing the test files in Splunk.
my bad- it would be inputs.conf for blacklisting.
And that will not index files that contain strings matching "Test".
Please remember to restart your splunkd.
Thanks! it rejects only file names with name Test right? or it search content of all files also?
Thank you so much for your help. Please confirm, it rejects only file names with Test or it will look for files content as well?
I have tested with the files which has "test" in word, but the file name is sample.txt and it is uploaded into splunk. So I think it is not looking into the content, only file name.