Splunk Search

Warning massage at splunkforwarder startup

RobertRi
Communicator

Hi

I have installed a 5.0.1 windows universal forwarder, and if i restart the uniforw. I get this message

Checking conf files for typos...                
Possible typo in stanza [monitor:C:\Program Files\Application Prod\logs] in C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf, line 6: blacklist  =  \.zip$
There might be typos in your conf files. For more information, run 'splunk btool check --debug'

If I run a splunk list monitor, then all zip files are excluded from monitoring and it works as desired

This is the inputs.conf

[default]
host = server1

[monitor:C:\Program Files\Application Prod\logs]
disabled = false
blacklist = \.zip$
index = application

Is there anything wrong in this stanza config?

Thanks
Rob

Tags (1)
0 Karma
1 Solution

kristian_kolb
Ultra Champion

It should say [monitor://c:\Program......etc.], i.e. you're missing the two slashes after monitor:

That's the only type I see.

/Kristian

View solution in original post

0 Karma

kristian_kolb
Ultra Champion

It should say [monitor://c:\Program......etc.], i.e. you're missing the two slashes after monitor:

That's the only type I see.

/Kristian

0 Karma

RobertRi
Communicator

Thanks, that was it

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...