Getting Data In

Blacklist patterns not working in inputs.conf

AnmolKohli
Explorer

I want to blacklist below two logs from my index.

Log 1: op_fe-run_autostat*
Log 2: op_fe-run_autostat*

I tried below configurations in inputs.conf but none of them are working. Can you please check.

Pattern 1:-

blacklist1 = op_fe-run_autostat*
blacklist2 = op_fe-proteus_prod_archive_E*

pattern 2:

blacklist= (op_fe-run_autostat* | op_fe-proteus_prod_archive_E*)

Pattern 3:

blacklist1 = source="op_fe-run_autostat*"
blacklist2 = source="op_fe-proteus_prod_archive_E*"

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The blacklist attribute uses regular expressions, not patterns. Try these settings.

blacklist= (op_fe-run_autostat.* | op_fe-proteus_prod_archive_E.*)
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...