Getting Data In

Inputs.conf whitelist syntax assistance

splunkingsplun1
Explorer

I have several virtual hosts under /opt/log/

/opt/log/webA

/opt/log/webB

/opt/log/webC

They all have denied.log that I need to index, would this be correct inputs.conf?

[monitor:///opt/log/www*]

sourcetype = apache

index=www

host_segment=3

whitelist = denied\.log$

Tags (1)
0 Karma

splunkingsplun1
Explorer

This worked:

[monitor:///opt/log/*]

index=web

host_segment=3

sourcetype = apache

index=www
whitelist = access.log$

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...