Getting Data In

Blacklist not working

ryu8450
New Member

Dear Experts,
I am trying to blacklist a log file.
My Stanza looks like this which is located in /opt/splunkforwarder/etc/apps/search/local/inputs.conf

[monitor:///www/a/logs/*.log]
blacklist = /www/a/logs/hotimportexport.log
disabled = false
index = main
sourcetype = Test

Can someone please tell me why my blacklist is not working?

Thanks,

Tags (1)
0 Karma

somesoni2
Revered Legend

Try removing the full path name from the blacklist attribute.

[monitor:///www/a/logs/*.log] 
blacklist = hotimportexport.log 
disabled = false 
index = main 
sourcetype = Test
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...