Is there a way to use external lists with whitelist filtering? For example if I had systems A and B with several hosts, could I create a list like hosts.txt and then refer to that list and its content? Something like below:
whitelist.0 = hosts.txt systemB
Thanks for any help!
I use this for managing a large number of hosts. In one case I temporarily used it with up to a nine thousand host entries.
Entry in the serverclass.conf
whitelist.from_pathname = etc/system/local/host.txt
restartSplunkd = 1
Do you know if that kind of a feature is added to Splunk in the future? It would make managing the serverclass.conf (and other confs too) a lot more easier if hosts could be centrally grouped.