I think I found the answer to my question when I was writing it.
From http://www.splunk.com/base/Documentation/4.1/Admin/Inputsconf I see that '_whitelist' was the old way, and in newer version (at least 4.1.4+) you skip the '_' and just use whitelist.
And the same goes for blacklist. Correct?
Correct you may now omit the "_".
Either one will work, but if you use both, only whitelist
/blacklist
will work (not _whitelist
/_blacklist
)