Getting Data In

Listing out all the inputs.conf

AL3Z
Builder

Hi, 

How we can list out all the apps inputs.conf blacklisted stanzas in the DS ? Coz I'm seeing the command line events are getting blocked in my Environment..

Thanks

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @AL3Z .. in linux, using the find and grep commands.. you can find all the blacklisted lines recursively.  

 

find . -name '*.conf' -exec grep -i 'blacklist' {}\; -print

 

grep -Ril "text-to-find-here" /

i stands for ignore case (optional in your case).
R stands for recursive.
l stands for "show the file name, not the result itself".
/ stands for starting at the root of your machine.

 

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

AL3Z
Builder

Hi @inventsekar ,

Can we check in the windows system ?

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...