Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why am I unable to blacklist all content in a certain directory with my current inputs.conf?

$
0
0
I am trying to blacklist the following in the inputs.conf Currently I have this: [monitor:///var/log] disabled = false blacklist = /manager/tomatod* index = os I have tried to blacklist all content that in the manager directory containing "tomatod" from ingesting. So far I have had no luck. The inputs.conf file is put into a deployment-app. Not sure what I am doing wrong. Please advise..

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>