Getting Data In

Inputs.conf

hartfoml
Motivator

I have this in my inputs.conf

_whitelist=(\.log|log$|^messages|^secure|mesg$|cron$|acpid$|\.out)

Can anyone help me understand what are the " ^ " and the " $ " are used for?

Tags (1)
1 Solution

BobM
Builder

These are known as anchors. They do not match any characters, they match a position. ^ matches at the start of the string, and $ matches at the end of the string.

Be careful though. In multiline strings, they can also match the beginning or end of a line and the ^ inside a square bracket can be used as a not as in [^a-z] which means not the characters a to z

View solution in original post

BobM
Builder

These are known as anchors. They do not match any characters, they match a position. ^ matches at the start of the string, and $ matches at the end of the string.

Be careful though. In multiline strings, they can also match the beginning or end of a line and the ^ inside a square bracket can be used as a not as in [^a-z] which means not the characters a to z

BobM
Builder

Yes the top line will match the words "messages", "secure" or "auth" anywhere in the file or folder name. The bottom will only match if it is at the beginning of the source.

As most sources start with the drive or a slash (i.e. c:\ or /), it is unlikely to match those.

hartfoml
Motivator

Thanks Bob,

I think I know what this is

can you tell me what the difference is in these two lines

whitelist=(\.log|log$|messages|secure|auth|mesg$|cron$|acpid$|\.out)

_whitelist=(\.log|log$|^messages|^secure|mesg$|cron$|acpid$|\.out)

These are on two different systems and I am not getting the same logs from both

Should I take out the " ^ " symbol?

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...