According to the documentation, it is this:
[monitor:///mnt/logs]
blacklist = .gz$
However, I've tried this and the many variations found in this knowledge base, and NONE of them are working!
Please help?
Please have a try
[monitor:///mnt/logs]
sourcetype=someSourcetype
index = myindex
blacklist = \.gz$
This example assumes that your gzip files all end with "gz" - lower case. How are your gzip files named?
That's precisely how they are named. It seems like it is now working? It looked like Splunk was finishing the file it had started and I couldn't stop it, even after a restart of the service.