Hi Splunk Community We have created few whitelist in our inputs.conf file. It was all fine until i try to enter the following: whitelist10=Type="Information" SourceName="Customer.Service" Message="*Request Info:ContactCustomer - CreateNewContact*" after restarting my splunk, i get the following: Invalid key in stanza [WinEventLog://Application] in C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf, line 38: whitelist12 (value: Type="Information" SourceName="Customer.Service" Message="*Request Info:ContactCustomer - CreateNewContact*"). and it gives me the following: Did you mean 'whitelist'? Did you mean 'whitelist1'? Did you mean 'whitelist2'? Did you mean 'whitelist3'? Did you mean 'whitelist4'? Did you mean 'whitelist5'? Did you mean 'whitelist6'? Did you mean 'whitelist7'? Did you mean 'whitelist8'? Did you mean 'whitelist9'? Is there a limit to number of whitelist we can create? Or what is the next correct key to use after whitelist9 ? thanks!! Azrad
... View more