Getting Data In
Highlighted

how to exclude indexing files starts with dot (.) and ending with .swp?

Builder

Can you please tell us, how to exclude files for indexing starts with dot (.) and ending with .swp.

currently we are using the command like below

./splunk add monitor /var/log/ -index abc sourcetype xyz

0 Karma
Highlighted

Re: how to exclude indexing files starts with dot (.) and ending with .swp?

Ultra Champion

locate the monitor stanza in inputs.conf (there can/will be more than one inputs.conf file), and make it like so;

[monitor:///var/log/]
index=abc
sourcetype=xyz
blacklist = /\.[^\\/]+\.swp$

/K

View solution in original post

Highlighted

Re: how to exclude indexing files starts with dot (.) and ending with .swp?

Builder

Can you please tell me how to avoid any filename starts with dot (.)? some the temp files also getting indexed with machine language format to avoid i want exclude those pattern as well.

0 Karma