Getting Data In

whitelist queries

athorat3
New Member

HI

I have a question
The existing whitelist in inputs.conf includes

whitelist = (tomcat|vizql|hs_err|tdeserver64)-[^/\\]*\.log$|(tdeserver|tabprotosrv|nativeapi)_vizqlserver.txt

 now there are new files added in the directory

    -a---         6/30/2017  11:58 AM          0 tabprotosrv_backgrounder_0-0.txt
    -a---         6/30/2017  12:03 PM     146491 tabprotosrv_backgrounder_0-0_1.txt
    -a---         6/30/2017  12:04 PM          0 tabprotosrv_backgrounder_0-0_10.txt
    -a---         6/30/2017  12:04 PM          0 tabprotosrv_backgrounder_0-0_11.txt
    -a---         6/30/2017  12:04 PM          0 tabprotosrv_backgrounder_0-0_12.txt
    -a---         6/30/2017  12:06 PM     123767 tabprotosrv_backgrounder_0-0_13.txt


how do I modify the existing whitelist to include these files
IS THE BELOW STANZA CORRECT?
whitelist = (tomcat|vizql|hs_err|tdeserver64)-[^/\\]*\.log$|(tdeserver|tabprotosrv|nativeapi)_vizqlserver.txt$|(tabprotosrv_backgrounder)[\_\d\-]*.txt
Tags (1)
0 Karma

DalJeanis
Legend

seems correct, but to be consistent you want a $ anchor after the final .txt, and you want to escape the period when you mean it to be a period (only).

whitelist = (tomcat|vizql|hs_err|tdeserver64)-[^/\\]*\.log$|(tdeserver|tabprotosrv|nativeapi)_vizqlserver\.txt$|(tabprotosrv_backgrounder)[\_\d\-]*\.txt$
0 Karma

horsefez
Motivator

Hey,

how about this regular expression.

(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$

Take a look at it here:
https://regex101.com/r/55M6LH/1

Tell me what you think about it.

0 Karma

athorat3
New Member

Thanks @horsefez

in the tail processing it says

C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_1_bk.txt

parent C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:.log|.txt)$'.

0 Karma

athorat3
New Member
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_1.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_10_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_10.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_11_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_11.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_12_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_12.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_13_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_13.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_14_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_14.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_15.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_16_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_16.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_17.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_18_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_18.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_19.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_2_bk.txt    
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...