Whitelists and blacklists will work for both directories and files. It's just that people always seem to use files in their examples...
Yep, I think that your ... could be in the wrong place. And I wonder if the [] in the regular expression will break the monitor stanza. It shouldn't, but...
You could do
[monitor:///var/log/splunk/10.10.10.13*]
blacklist=/10\.10\.10\.(130|131)/
But before you change anything, run this
./splunk cmd btool inputs list --debug >inputs.debug.list
This may help - it shows how all the input.conf stanzas are combined. This won't catch everything, but it may give you some insight.
Use btool to troubleshoot configurations
... View more