Getting Data In

Whitelist Would not work

asarolkar
Builder

The following logs in Weblogic are being captured in inputs.conf

mydomain.log1123213123 mydomain.log4353245254

myserver.log3423423423 myserver.log566999999

access.log34324324324 access.log234324324

We did this using the following whitelist ->

[ monitor://c:\bea\user_projects\domains\mydomain ]

disabled = 0

whitelist = mydomain.log*

index = main

sourcetype = mydomain

[ monitor://c:\bea\user_projects\domains\mydomain\myserver ]

disabled = 0

whitelist = myserver.log*

index = main

sourcetype = myserver

But that does not seem to be helping.

Any suggestions ?

0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

That is not a valid regex that would match your log file name. Try:

whitelist=myserver\.log.*

View solution in original post

araitz
Splunk Employee
Splunk Employee

That is not a valid regex that would match your log file name. Try:

whitelist=myserver\.log.*
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...