Splunk Enterprise

How to Blacklist Hosts at the Indexer

lpolo
Motivator

Let's say, I have 5 forwarders. 4 of them are allowed to forward events to the indexer but one of them is not. How can I Blacklist this host at the indexer not at the forwarder or network (eg., iptables)? In this way, no log event should be index from the host that is not allowed to...

Thanks,
Lp

Tags (1)
0 Karma

starcher
Influencer

I guess I am confused. if the forwarder is never allowed to send events to an indexer why even leave it installed. I would just remove it.

0 Karma

JSapienza
Contributor

Something like this might work then :

props.conf

[Host::myhost]
TRANSFORM-myhost=rejectHost

transforms.conf

[rejectHost]
REGEX = .*
DEST=queue
FORMAT=nullQueue

JSapienza
Contributor

That would be a whitelist not a blacklist. Am I not sure that can be done in this manner. I would urge you to look in to using deployment server to modify the outputs.conf.

0 Karma

lpolo
Motivator

What about if you do not know the name of the host that you want to blacklist but you know the hosts that are allowed.

Thanks,
Lp

0 Karma

lpolo
Motivator

This approach cannot be done. We do not have configuration control of the forwarders.

0 Karma

JSapienza
Contributor

If it were me I would approach this from a different direction. Why even send the data over the wire to the indexer only to be dumped to the nullQueue ? You could use the deployment server to send an app to the forwarder with an an empty outputs.conf or one that didn't have the indexer/s listed. This way at a later time all you have to do is remove that host from the corresponding severClass to revert the changes and allow it to communicate with the indexer.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...