Getting Data In

Inputs.conf

hartfoml
Motivator

I have this in my inputs.conf

_whitelist=(\.log|log$|^messages|^secure|mesg$|cron$|acpid$|\.out)

Can anyone help me understand what are the " ^ " and the " $ " are used for?

Tags (1)
1 Solution

BobM
Builder

These are known as anchors. They do not match any characters, they match a position. ^ matches at the start of the string, and $ matches at the end of the string.

Be careful though. In multiline strings, they can also match the beginning or end of a line and the ^ inside a square bracket can be used as a not as in [^a-z] which means not the characters a to z

View solution in original post

BobM
Builder

These are known as anchors. They do not match any characters, they match a position. ^ matches at the start of the string, and $ matches at the end of the string.

Be careful though. In multiline strings, they can also match the beginning or end of a line and the ^ inside a square bracket can be used as a not as in [^a-z] which means not the characters a to z

BobM
Builder

Yes the top line will match the words "messages", "secure" or "auth" anywhere in the file or folder name. The bottom will only match if it is at the beginning of the source.

As most sources start with the drive or a slash (i.e. c:\ or /), it is unlikely to match those.

hartfoml
Motivator

Thanks Bob,

I think I know what this is

can you tell me what the difference is in these two lines

whitelist=(\.log|log$|messages|secure|auth|mesg$|cron$|acpid$|\.out)

_whitelist=(\.log|log$|^messages|^secure|mesg$|cron$|acpid$|\.out)

These are on two different systems and I am not getting the same logs from both

Should I take out the " ^ " symbol?

Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...