Getting Data In

whitelist queries

athorat3
New Member

HI

I have a question
The existing whitelist in inputs.conf includes

whitelist = (tomcat|vizql|hs_err|tdeserver64)-[^/\\]*\.log$|(tdeserver|tabprotosrv|nativeapi)_vizqlserver.txt

 now there are new files added in the directory

    -a---         6/30/2017  11:58 AM          0 tabprotosrv_backgrounder_0-0.txt
    -a---         6/30/2017  12:03 PM     146491 tabprotosrv_backgrounder_0-0_1.txt
    -a---         6/30/2017  12:04 PM          0 tabprotosrv_backgrounder_0-0_10.txt
    -a---         6/30/2017  12:04 PM          0 tabprotosrv_backgrounder_0-0_11.txt
    -a---         6/30/2017  12:04 PM          0 tabprotosrv_backgrounder_0-0_12.txt
    -a---         6/30/2017  12:06 PM     123767 tabprotosrv_backgrounder_0-0_13.txt


how do I modify the existing whitelist to include these files
IS THE BELOW STANZA CORRECT?
whitelist = (tomcat|vizql|hs_err|tdeserver64)-[^/\\]*\.log$|(tdeserver|tabprotosrv|nativeapi)_vizqlserver.txt$|(tabprotosrv_backgrounder)[\_\d\-]*.txt
Tags (1)
0 Karma

DalJeanis
Legend

seems correct, but to be consistent you want a $ anchor after the final .txt, and you want to escape the period when you mean it to be a period (only).

whitelist = (tomcat|vizql|hs_err|tdeserver64)-[^/\\]*\.log$|(tdeserver|tabprotosrv|nativeapi)_vizqlserver\.txt$|(tabprotosrv_backgrounder)[\_\d\-]*\.txt$
0 Karma

horsefez
Motivator

Hey,

how about this regular expression.

(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$

Take a look at it here:
https://regex101.com/r/55M6LH/1

Tell me what you think about it.

0 Karma

athorat3
New Member

Thanks @horsefez

in the tail processing it says

C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_1_bk.txt

parent C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:.log|.txt)$'.

0 Karma

athorat3
New Member
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_1.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_10_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_10.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_11_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_11.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_12_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_12.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_13_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_13.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_14_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_14.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_15.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_16_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_16.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_17.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_18_bk.txt   
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_18.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_19.txt  
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\tabprotosrv_backgrounder_0-0_2_bk.txt    
parent  C:\ProgramData\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\
type    File did not match whitelist '(?:^)(?:tomcat|vizql|hs_err|tdeserver|tabprotosrv|nativeapi)(?:.*)(?:\.log|\.txt)$'.
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...