Splunk Search

blacklist not working * condition

puneethgowda
Communicator

sourcetype=XyzProd
blacklist = MethodExecutionInfo(\d{8})-(\d{2}).txt|DebugInfo(\d{8})-(\d{2}).txt|CacheRefreshInfo(\d{8})-(\d{2}).txt

I want to add below one

|currency(\d{8})-(\d{2}).txt
It's not working

Tags (1)
0 Karma

puneethgowda
Communicator

(MethodExecutionInfo|DebugInfo|CacheRefreshInfo|.currency.)((\d{8})-(\d{2})).txt

Got the answer from slack

0 Karma