Getting Data In

Whats the difference between _whitelist and whitelist?

Joffer
Path Finder

I think I found the answer to my question when I was writing it.

From http://www.splunk.com/base/Documentation/4.1/Admin/Inputsconf I see that '_whitelist' was the old way, and in newer version (at least 4.1.4+) you skip the '_' and just use whitelist.

And the same goes for blacklist. Correct?

Tags (1)
0 Karma
1 Solution

rroberts
Splunk Employee
Splunk Employee

Correct you may now omit the "_".

View solution in original post

rroberts
Splunk Employee
Splunk Employee

Correct you may now omit the "_".

gkanapathy
Splunk Employee
Splunk Employee

Either one will work, but if you use both, only whitelist/blacklist will work (not _whitelist/_blacklist)

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...