Getting Data In

blacklist in batch stanza

carmackd
Communicator

Can I use blacklist in a batch stanza? I couldn't find anything in the documentation saying otherwise.

Thanks,

Tags (1)
1 Solution

Mick
Splunk Employee
Splunk Employee

The answer is actually yes, you should be able to use white & blacklist settings for sinkhole directories (batch inputs). The underlying logic is the same for both monitor and batch inputs, the only difference being that batch is destructive and will delete your data.

I'll get the docs updated to reflect this.

View solution in original post

Mick
Splunk Employee
Splunk Employee

The answer is actually yes, you should be able to use white & blacklist settings for sinkhole directories (batch inputs). The underlying logic is the same for both monitor and batch inputs, the only difference being that batch is destructive and will delete your data.

I'll get the docs updated to reflect this.

netwrkr
Communicator

According to what I read, the answer is no.

"Use whitelist and blacklist rules to explicitly tell Splunk which files to consume when monitoring directories."

http://www.splunk.com/base/Documentation/4.1.2/Admin/Whitelistorblacklistspecificincomingdata

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...