Getting Data In

blacklist in batch stanza

carmackd
Communicator

Can I use blacklist in a batch stanza? I couldn't find anything in the documentation saying otherwise.

Thanks,

Tags (1)
1 Solution

Mick
Splunk Employee
Splunk Employee

The answer is actually yes, you should be able to use white & blacklist settings for sinkhole directories (batch inputs). The underlying logic is the same for both monitor and batch inputs, the only difference being that batch is destructive and will delete your data.

I'll get the docs updated to reflect this.

View solution in original post

Mick
Splunk Employee
Splunk Employee

The answer is actually yes, you should be able to use white & blacklist settings for sinkhole directories (batch inputs). The underlying logic is the same for both monitor and batch inputs, the only difference being that batch is destructive and will delete your data.

I'll get the docs updated to reflect this.

netwrkr
Communicator

According to what I read, the answer is no.

"Use whitelist and blacklist rules to explicitly tell Splunk which files to consume when monitoring directories."

http://www.splunk.com/base/Documentation/4.1.2/Admin/Whitelistorblacklistspecificincomingdata

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...