Getting Data In

Multiple Eventcodes in same Blacklist

helpmelearn
Explorer

Hello 

We are trying to change the below blacklists: 


blacklist3 = EventCode="4690" 
blacklist4 = EventCode="5145"
blacklist5 = EventCode="5156"
blacklist6 = EventCode="4658"
blacklist7 = EventCode="5158"

To a single blacklist with multiple eventcodes. We have tried:

blacklist3 = EventCode=5145,5156,4658,4690,5158

and

blacklist3 = EventCode="5145" OR "5156" OR "4658" OR "4690" OR "5158"

And none of these are applying and blocking out the event codes. 

 

Any recommendations on how to get this to work? 

 

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The syntax is incorrect.  A blacklist must be a comma-separated list of event IDs or pairs of key=regex specifiers.  Try this

blacklist3 = 5145,5156,4658,4690,5158
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The syntax is incorrect.  A blacklist must be a comma-separated list of event IDs or pairs of key=regex specifiers.  Try this

blacklist3 = 5145,5156,4658,4690,5158
---
If this reply helps you, Karma would be appreciated.

helpmelearn
Explorer

Thankyou! This worked 😄 

Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials

Welcome to the "Splunk Classroom Chronicles" series, created to help curious, career-minded learners get ...

Access Tokens Page - New & Improved

Splunk Observability Cloud recently launched an improved design for the access tokens page for better ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...