Getting Data In

Splunk 9 blacklist or denylist?

TheEggi98
Path Finder

Did the blacklist/whitelist got replaced by denylist/allowlist in Splunk 9?

In some Blogs i read that Splunk 9 replaced blacklist with denylist? Or is blacklist still usable?

In the Changelogs of Splunk 9 i didnt found any evidence for the change, but the Splexicon and some Blogs say something different.

https://docs.splunk.com/Splexicon:Denylist
https://www.splunk.com/en_us/blog/leadership/biased-language-has-no-place-in-tech-a-follow-up.html?l...

Thanks for explanation 🙂

Labels (3)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

You could/should check what are the currently used versions on your installation. There are in directory $SPLUNK_HOME/etc/system/README/<conf file>.conf.spec, where are known configurations. 

With quick check it seems that e.g. inputs.conf still known white- and blacklists.

You could also check these from Splunk Docs e.g. https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

You could/should check what are the currently used versions on your installation. There are in directory $SPLUNK_HOME/etc/system/README/<conf file>.conf.spec, where are known configurations. 

With quick check it seems that e.g. inputs.conf still known white- and blacklists.

You could also check these from Splunk Docs e.g. https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

r. Ismo

Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...