Deployment Architecture

Forward to indexer all except from particular path

Wojt3k
Engager

Hello,

I would like to exclude just one user from forwarding logs and I am thinking if my solution will work:

in inputs.conf I would like to define:

[monitor:///home/nessus/.bash_history]
disabled = true

[monitor:///home/*/.bash_history]
disabled = false

The goal is to exclude logging data from user nessus but to log everybody else.

I am not sure if it's a good solution, maybe someone has better idea? 

Labels (2)
0 Karma
1 Solution

manjunathmeti
Champion

hi @Wojt3k,

You can use deny list.

[monitor:///home/*/.bash_history]
blacklist=nessus

View solution in original post

0 Karma

m_pham
Splunk Employee
Splunk Employee
0 Karma

manjunathmeti
Champion

hi @Wojt3k,

You can use deny list.

[monitor:///home/*/.bash_history]
blacklist=nessus
0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...