Skip to content

Latest commit

 

History

History
62 lines (51 loc) · 1.77 KB

splunk_forwarder_install_linux.md

File metadata and controls

62 lines (51 loc) · 1.77 KB

dont foward files

Add blacklist to not forward certain files

  • blacklist = pihole*
  • blacklist = access*

inputs.conf - fine tuned for controlling indexs and sources when searching

[monitor:///var/log/secure]
sourcetype = linux_secure
source = secure
disabled = 0

[monitor:///var/log/messages]
disabled = 0
source = messages
sourcetype = syslog

[monitor:///root/.bash_history]
source = bash_history
sourcetype = syslog
disabled = 0

[monitor:///home/.../.bash_history]
source = bash_history
sourcetype = syslog
disabled = 0

[monitor:///var/log/auth.log*]
blacklist = (\.gz$|\.zip$|\.bz2$)
source = auth
sourcetype = syslog
disabled = 0

[monitor:///var/log]
whitelist = (log$|messages|mesg$|cron$|acpid$|\.out)
blacklist = (\.gz$|\.zip$|\.bz2$|auth\.log|lastlog|secure|anaconda\.syslog)
source = linux_logs
sourcetype = syslog
disabled = 0

REFS: