Monitoring Splunk

how to exclude .txt file in log directory from monitoring??

saifuddin9122
Path Finder

Hello,

i have log directory in which all files need to be monitored but i need to exclude file with .txt
am sure that i can do it with by mentioning black list

but the problem is my log file will be in abc.date.txt format.
can i use black list here if so can anyone let me know how??

Thanks in advance

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

Like this (inside the appropriate stanza inside of inputs.conf):

blacklist = \.\d+\.(txt)$

View solution in original post

0 Karma

woodcock
Esteemed Legend

Like this (inside the appropriate stanza inside of inputs.conf):

blacklist = \.\d+\.(txt)$
0 Karma

saifuddin9122
Path Finder

Thanks it worked.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...