Splunk ITSI

blocking specific input files

bhagyashrihegde
New Member

Hi Team,

We are using Splunk Enterprise on AWS environment. So long back there is an Cloudtrial app configured on the same. Logs are directly getting pushed to splunk indexer through S3 bucket based on the inputs configured on the Coudtrial app. Since this App version is old, there is no option to configure the inputs through GUI. we are making changes through inputs.conf file itself.

I've to block the Decrypt logs (.gz) getting indexed from the splunk. please suggest the work around for the same. Let us know if this cloud trial App has to be upgraded for the same and what will be the latest version of this.

0 Karma

acfecondo75
Path Finder

Hello,

You can use blacklist within inputs.conf to exclude any files ending in .gz. For whichever input stanza is bringing in the AWS data, add:

blacklist=.gz$

More info on blacklist:

blacklist = regex

  • If set, files from this input are NOT monitored if their path matches the
    specified regex.
  • Takes precedence over the deprecated '_blacklist' setting, which functions the same way.
  • If a file matches the regexes in both the blacklist and whitelist settings,
    the file is NOT monitored. Blacklists take precedence over whitelists.
  • No default.

Hopefully that helps!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...