Splunk Enterprise

exclude a file from a directory of log files being indexed

wbcattell
Explorer

I have one file - 101-wallet42A_yyyyMMdd_hhmm.log - which is a binary file in a directory full of log files I'm having forwarded to my indexer.

How can I put in an exclusion so this file will not be accessed by the forwarder?

TIA,

Bill

Tags (2)
0 Karma

bob87
Explorer

To exclude this file from being picked up by the forwarder, I think you can use a blacklist (see http://docs.splunk.com/Documentation/Splunk/5.0.1/Data/Whitelistorblacklistspecificincomingdata)

wbcattell
Explorer

Very cool. Exactly what I needed. Thanks dude.

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...