Deployment Architecture

How to acknowledge the blacklist working or not ??

AL3Z
Builder

Hi Everyone,

I've recently applied a blacklist file path regex to one of the apps inputs.conf in the serverclass on the host in DS. How can I determine  it's working or not?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you no longer see data from the blocked data source then the denylist is working.

---
If this reply helps you, Karma would be appreciated.

AL3Z
Builder

Can you pls share the spl command.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You just search for events which have your file(s) as source field value. If they stopped being ingested at some point your blacklisting works. Unless of course you have some additional config overwriting the source field but then it's up to you to find those events - we don't know your setup.

Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...