Getting Data In

Splunk 9 blacklist or denylist?

TheEggi98
Path Finder

Did the blacklist/whitelist got replaced by denylist/allowlist in Splunk 9?

In some Blogs i read that Splunk 9 replaced blacklist with denylist? Or is blacklist still usable?

In the Changelogs of Splunk 9 i didnt found any evidence for the change, but the Splexicon and some Blogs say something different.

https://docs.splunk.com/Splexicon:Denylist
https://www.splunk.com/en_us/blog/leadership/biased-language-has-no-place-in-tech-a-follow-up.html?l...

Thanks for explanation 🙂

Labels (3)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

You could/should check what are the currently used versions on your installation. There are in directory $SPLUNK_HOME/etc/system/README/<conf file>.conf.spec, where are known configurations. 

With quick check it seems that e.g. inputs.conf still known white- and blacklists.

You could also check these from Splunk Docs e.g. https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

You could/should check what are the currently used versions on your installation. There are in directory $SPLUNK_HOME/etc/system/README/<conf file>.conf.spec, where are known configurations. 

With quick check it seems that e.g. inputs.conf still known white- and blacklists.

You could also check these from Splunk Docs e.g. https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

r. Ismo

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...