Hi Everyone,
I've recently applied a blacklist file path regex to one of the apps inputs.conf in the serverclass on the host in DS. How can I determine it's working or not?
If you no longer see data from the blocked data source then the denylist is working.
Can you pls share the spl command.
You just search for events which have your file(s) as source field value. If they stopped being ingested at some point your blacklisting works. Unless of course you have some additional config overwriting the source field but then it's up to you to find those events - we don't know your setup.