Getting Data In

Whats the difference between _whitelist and whitelist?

Joffer
Path Finder

I think I found the answer to my question when I was writing it.

From http://www.splunk.com/base/Documentation/4.1/Admin/Inputsconf I see that '_whitelist' was the old way, and in newer version (at least 4.1.4+) you skip the '_' and just use whitelist.

And the same goes for blacklist. Correct?

Tags (1)
0 Karma
1 Solution

rroberts
Splunk Employee
Splunk Employee

Correct you may now omit the "_".

View solution in original post

rroberts
Splunk Employee
Splunk Employee

Correct you may now omit the "_".

gkanapathy
Splunk Employee
Splunk Employee

Either one will work, but if you use both, only whitelist/blacklist will work (not _whitelist/_blacklist)

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...