Getting Data In

Why is my blacklist regular expression not working?

arohde
New Member

Watching: /var/log (across 6 servers)

Blacklist:

(audit|(\.gz$))

Result: still uploads at least a gig of /var/log/audit/audit.log every day. I feel like I've tried everything (tweaking the regular expression, restarting Splunk, waiting)

0 Karma

DalJeanis
Legend

I'd try this

blacklist = (?i:.*?\/audit\/.*$|.*\.gz$)

The initial flag just sets it case insensitive. Then we have a choice of either any name with "/audit/" anywhere in it, lazy before, greedy after, or any file ending in .gz, greedy before because we're only backtracking at the end-of-field marker and that won't take long.

Most of the answer came from here...

https://answers.splunk.com/answers/30645/cant-get-a-blacklist-to-work-please-help.html

and here ...

http://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata?r=s...

0 Karma

arohde
New Member

So I tried that in the web interface, but I'm not seeing it change anything. I say that because when I search source=/var/log/audit/audit.log it shows contents still being uploaded. Is there something I'd have to do to make this take effect? Again, I'm only using the web interface so far.

0 Karma

dcarmack_splunk
Splunk Employee
Splunk Employee

can you give examples of filenames in the monitored directory?

0 Karma

arohde
New Member

so UPDATE: If I put the exact same regex in my inputs.conf it works fine. just NOT IN THE WEB INTERFACE.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...